CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-61907: icinga 2.15.0; +1 more affected products

CVE-2025-61907. CVSS 3.1 base score 6.5 (MEDIUM, NVD). EPSS 0.00404 (percentile 0.32511), scored 2026-10-08.

Affected technology

icinga · from 2.4.0 (inclusive), before 2.13.13 (exclusive)
icinga

icinga · from 2.14.0 (inclusive), before 2.14.7 (exclusive)
icinga

icinga · 2.15.0
icinga

icinga2 · >= 2.15.0, < 2.15.1, >= 2.14.0, < 2.14.7, >= 2.4.0, < 2.13.13
Icinga

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Authenticated API users can learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. Vendor/CNA’s CVSS 4.0 assessment (base score 7.1/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-200, CWE-204, CWE-749
CCR priority
26.1 /100 (P4)
CVSS 3.1
6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N · NVD
EPSS
0.00404 · percentile 0.32511 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-61907.html