SB2025052757 - Node impersonation through unauthorized certificate renewal in Icinga
Published: May 27, 2025
Security Bulletin ID
SB2025052757
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper certificate validation (CVE-ID: CVE-2025-48057)
The vulnerability allows a remote attacker to impersonate trusted nodes.
The vulnerability exists due to an error within the VerifyCertificate() function that can be tricked into issuing a valid certificate. A remote attacker can send a specially crafted certificate request and request renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes.
Remediation
Install update from vendor's website.