Memory Exhaustion Vulnerability in Icinga Monitoring Software by Icinga
CVE-2018-6532

7.5HIGH

Key Information:

Vendor

Icinga

Status
Vendor
CVE Published:
27 February 2018

What is CVE-2018-6532?

The Icinga monitoring software is susceptible to a vulnerability that allows attackers to send specially crafted requests, both authenticated and unauthenticated. This can lead to excessive memory consumption on the server, prompting the server's Out of Memory (OOM) killer to trigger, potentially disrupting service and causing denial of service. This issue affects Icinga 2.x up to version 2.8.1, necessitating prompt attention from system administrators to patch vulnerabilities and secure their infrastructure.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.