CVE-2022-24715

HIGH

Icinga Web 2 <2.8.6-2.10 - Authenticated RCE

Title source: llm

Description

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.

Exploits (5)

exploitdb WORKING POC
by Dante Corona · pythonwebappsphp
https://www.exploit-db.com/exploits/51586
nomisec WORKING POC 16 stars
by JacobEbben · poc
https://github.com/JacobEbben/CVE-2022-24715
nomisec WORKING POC
by d4rkb0n3 · poc
https://github.com/d4rkb0n3/CVE-2022-24715-go
nomisec WORKING POC
by cxdxnt · poc
https://github.com/cxdxnt/CVE-2022-24715
nomisec WORKING POC
by nimphtix · poc
https://github.com/nimphtix/CVE-2022-24715

Scores

CVSS v3 8.5
EPSS 0.7251
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
icinga/icinga_web_2 < 2.8.6
Published Mar 08, 2022
Tracked Since Feb 18, 2026