logo

Critical Icinga 2 Vulnerability Allows Attackers to Obtain Valid Certificates

ID: c76b5024-d830-50f5-9ade-42774da88152

STIX ID: report--c76b5024-d830-50f5-9ade-42774da88152

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-05-30

Date Updated: 2026-04-19

Author: Mayura

...
...

Security researchers disclosed a critical vulnerability in Icinga 2 affecting installations that use OpenSSL versions prior to 1.1.0 (notably RHEL 7 and derivatives). The flaw in the VerifyCertificate() function can be abused to have the Icinga CA issue legitimate certificates for attacker-controlled requests, enabling impersonation of trusted nodes if an attacker can establish a direct TLS connection to a signing master. Patches (Icinga 2.14.6, 2.13.12, 2.12.12) and temporary mitigations (restricting master access or disabling certificate signing by renaming the CA directory) have been released, and updated binaries and source are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.