Improper certificate validation in Icinga - CVE-2025-48057
Published: May 27, 2025
Icinga
Detailed vulnerability description
The vulnerability allows a remote attacker to impersonate trusted nodes.
The vulnerability exists due to an error within the VerifyCertificate() function that can be tricked into issuing a valid certificate. A remote attacker can send a specially crafted certificate request and request renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes.