#VU109861 Improper certificate validation in Icinga - CVE-2025-48057
Published: May 27, 2025
Icinga
Icinga
Description
The vulnerability allows a remote attacker to impersonate trusted nodes.
The vulnerability exists due to an error within the VerifyCertificate() function that can be tricked into issuing a valid certificate. A remote attacker can send a specially crafted certificate request and request renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes.