peter bassill · operator
$ cve CVE-2022-24715 JSON

CVE-2022-24715 EXPLOIT

8.5
HIGH · CVSS 3.1 · EPSS 14.7% (pctl 97)

Patch early

A public exploit exists.

Description

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.

Scoring

CVSS8.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS14.67% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2022-03-08
Last modified2026-06-17

Affected (1)

VendorProduct
icingaicinga web 2

Public exploits

SourceTitleDate
exploit-dbIcinga Web 2.10 - Authenticated Remote Code Execution2023-07-15

References

→ the Explorer  ·  watch your stack  ·  NVD