Impact
The vulnerability arises from improper access control in the JSON‑RPC certificate update messages. An unauthenticated attacker who can reach TCP port 5665 can send a crafted request that replaces the node certificate and trusted CA certificate. By doing so, the attacker can impersonate a trusted node, gain full control over the monitored node, and potentially execute arbitrary code, providing complete system compromise. This weakness is classified as CWE-862.
Affected Systems
Affected systems include the Icinga monitoring platform, specifically Icinga2. Versions from 2.8 up to 2.14.8 are vulnerable, and the issue has been fixed in releases 2.14.9, 2.15.4, and 2.16.2. These vulnerable releases lack proper validation when handling certificate update JSON‑RPC requests, allowing an attacker to replace node certificates and impersonate trusted nodes.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. Since the EPSS score is not available, the risk remains high; attackers who can reach TCP port 5665 can exploit the vulnerability on vulnerable releases up to 2.14.8. The issue is not listed in CISA KEV catalog, but the high CVSS and the potential for complete node takeover warrant immediate attention. Network‑based attackers can execute the vulnerability without authentication, underscoring the need to close the exposure promptly.
OpenCVE Enrichment
Debian DSA