Icinga vulnerabilities
32 known vulnerabilities affecting icinga/icinga.
Total CVEs
32
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH12MEDIUM16LOW1
Vulnerabilities
Page 1 of 2
CVE-2012-6096P2HIGHCVSS 7.5PoCv1.6.0v1.6.1+8 more2013-01-22
CVE-2012-6096 [HIGH] CWE-119 CVE-2012-6096: Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core befo
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.
nvd
CVE-2013-7108P3MEDIUMCVSS 5.5PoC≤ 1.8.4v0.8.0+32 more2014-01-15
CVE-2013-7108 [MEDIUM] CWE-20 CVE-2013-7108: Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 be
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (
nvd
CVE-2024-49369P2CRITICALCVSS 9.8≥ 2.4.0, < 2.11.12≥ 2.12.0, < 2.12.11+2 more2024-11-12
CVE-2024-49369 [CRITICAL] CWE-295 CVE-2024-49369: Icinga is a monitoring system which checks the availability of network resources, notifies users of
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client
nvd
CVE-2021-32743P3HIGHCVSS 8.8≥ 2.0.0, < 2.11.10≥ 2.12.0, < 2.12.52021-07-15
CVE-2021-32743 [HIGH] CWE-202 CVE-2021-32743: Icinga is a monitoring system which checks the availability of network resources, notifies users of
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to a
nvd
CVE-2025-48057P3CRITICALCVSS 9.8fixed in 2.12.12≥ 2.13.0, < 2.13.12+1 more2025-05-27
CVE-2025-48057 [CRITICAL] CWE-296 CVE-2025-48057: Icinga 2 is a monitoring system which checks the availability of network resources, notifies users o
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious cer
nvd
CVE-2011-2179P4MEDIUMCVSS 4.3PoC≤ 1.4.0v0.8.0+12 more2011-06-14
CVE-2011-2179 [MEDIUM] CWE-79 CVE-2011-2179: Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 an
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.
nvdosv
CVE-2021-32739P3HIGHCVSS 8.8≥ 2.4.0, < 2.11.10≥ 2.12.0, < 2.12.52021-07-15
CVE-2021-32739 [HIGH] CWE-267 CVE-2021-32739: Icinga is a monitoring system which checks the availability of network resources, notifies users of
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user's credentials, an attacker can view most attrib
nvd
CVE-2020-29663P3CRITICALCVSS 9.1≥ 2.8.0, ≤ 2.11.7v2.12.22020-12-15
CVE-2020-29663 [CRITICAL] CWE-295 CVE-2020-29663: Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
nvd
CVE-2021-37698P3HIGHCVSS 7.5≥ 2.5.0, < 2.11.10≥ 2.12.0, < 2.12.6+1 more2021-08-19
CVE-2021-37698 [HIGH] CWE-295 CVE-2021-37698: Icinga is a monitoring system which checks the availability of network resources, notifies users of
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server's certificate despite a certificate authority being specified. Icinga 2
nvd
CVE-2020-14004P3HIGHCVSS 7.8≥ 2.0.0, ≤ 2.11.3v2.12.02020-06-12
CVE-2020-14004 [HIGH] CWE-59 CVE-2020-14004: An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the i
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged
nvd
CVE-2018-6535P3HIGHCVSS 8.1≥ 2.0.0, ≤ 2.8.12018-02-27
CVE-2018-6535 [HIGH] CVE-2018-6535: An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison
An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.
nvd
CVE-2018-6532P3HIGHCVSS 7.5≥ 2.0.0, ≤ 2.8.02018-02-27
CVE-2018-6532 [HIGH] CWE-400 CVE-2018-6532: An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and
An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.
nvd
CVE-2024-24820P3HIGHCVSS 8.3≥ 1.0.0, < 1.8.2≥ 1.9.0, < 1.9.2+2 more2024-02-09
CVE-2024-24820 [HIGH] CWE-352 CVE-2024-24820: Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga D
Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the monitoring environment managed by Icinga Director without the awareness o
nvd
CVE-2025-61907P3MEDIUMCVSS 6.5≥ 2.4.0, < 2.13.13≥ 2.14.0, < 2.14.7+1 more2025-10-16
CVE-2025-61907 [MEDIUM] CWE-200 CVE-2025-61907: Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expres
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variabl
nvd
CVE-2018-6533P3HIGHCVSS 7.8≥ 2.0.0, ≤ 2.8.12018-02-27
CVE-2018-6533 [HIGH] CVE-2018-6533: An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be
An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).
nvd
CVE-2017-16882P3HIGHCVSS 7.8≤ 1.14.02017-11-18
CVE-2017-16882 [HIGH] CVE-2017-16882: Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects
nvd
CVE-2021-32747P3MEDIUMCVSS 6.5≥ 2.0.0, < 2.7.5≥ 2.8.0, < 2.8.32021-07-12
CVE-2021-32747 [MEDIUM] CWE-200 CVE-2021-32747: Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vu
Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed to unauthorized users exists between versions 2.0.0 and 2.8.2. Custom variables are user-defined keys and values on configuration objects in Icinga 2. These are commonly used to reference secrets in ot
nvd
CVE-2025-61908P3MEDIUMCVSS 6.5≥ 2.10.0, < 2.13.13≥ 2.14.0, < 2.14.7+1 more2025-10-16
CVE-2025-61908 [MEDIUM] CWE-476 CVE-2025-61908: Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, whe
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with access to an API endpoint that allows specifying a filter expression to crash the Icinga 2 daemon. A fix
nvd
CVE-2012-3441P3HIGHCVSS 7.5v1.7.12012-08-25
CVE-2012-3441 [HIGH] CWE-264 CVE-2012-3441: The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants a
The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.
nvd
CVE-2013-7106P3MEDIUMCVSS 6.5≤ 1.8.4v0.8.0+32 more2014-01-15
CVE-2013-7106 [MEDIUM] CWE-119 CVE-2013-7106: Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10
Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutil
nvdosv
1 / 2Next →