Sploitus

CVE-2024-49369

2 known exploits for CVE-2024-49369

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client certificates for authentication (ApiUser objects with the client_cn attribute set). This vulnerability has been fixed in v2.14.3, v2.13.10, v2.12.11, and v2.11.12.

Affected products
Alt Linux, Icinga 2
Icinga
< 2.11.12, 2.12.11, 2.13.10, 2.14.3
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
2.9% (86th percentile)
Weakness
CWE-295
NVD status
Analyzed
Published
2024-11-12
CVE-2024-49369 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2024-49369

Proof-of-concept code and exploit modules indexed by Sploitus