← back
CVE-2022-24715highCWE-22

Arbitrary code execution for authenticated users in Icinga Web 2

46Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.5epss 15%
from disclosure to weapon382 days
Published on NVDMar 8
1st PoC+382d
exploitation probability
15%top 4% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Icinga · icingaweb2
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.