Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-49369


Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client certificates for authentication (ApiUser objects with the client_cn attribute set). This vulnerability has been fixed in v2.14.3, v2.13.10, v2.12.11, and v2.11.12.


Published

2024-11-12T17:15:08.250

Last Modified

2025-11-26T13:01:15.760

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application icinga icinga < 2.11.12 Yes
Application icinga icinga < 2.12.11 Yes
Application icinga icinga < 2.13.10 Yes
Application icinga icinga < 2.14.3 Yes
Operating System debian debian_linux 11.0 Yes

References