CVE-2022-24715
Arbitrary code execution for authenticated users in Icinga Web 2
- Published
- Mar 8, 2022
- Updated
- Apr 23, 2025
- Assigning CNA
- GitHub_M
- Evidence observed
- Jul 15, 2023
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 96.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.
Sources
4- CVE-2022-24715Exploit
Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10
- CVE-2022-24715-goExploit
Go-based exploit for Icinga Web 2 (CVE-2022-24715) enabling remote code execution against vulnerable instances. Port of original Python PoC.
- CVE-2022-24715Exploit
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.