Skip to content
Threat Feed
medium advisory

Multiple Vulnerabilities in Icinga Web

Remote attackers can exploit multiple vulnerabilities in Icinga Web to conduct Denial of Service attacks or disclose sensitive information due to improper request handling.

CVE search metadata

CVE search record: CVE-2024-24757. Severity: high. CVSS: 7.6. EPSS: 0.53%. KEV: no. Product: Icinga Web. Brief: Multiple Vulnerabilities in Icinga Web. Brief link: https://feed.craftedsignal.io/briefs/2026-08-icinga-vulnerabilities/

CVE search record: CVE-2024-24758. Severity: low. CVSS: 3.9. EPSS: 0.77%. KEV: no. Product: Icinga Web. Brief: Multiple Vulnerabilities in Icinga Web. Brief link: https://feed.craftedsignal.io/briefs/2026-08-icinga-vulnerabilities/

Icinga has announced multiple security vulnerabilities (CVE-2024-24757 and CVE-2024-24758) affecting Icinga Web. These flaws allow a remote, unauthenticated attacker to impact the availability of the monitoring interface through Denial of Service (DoS) conditions or gain access to unauthorized information. The vulnerabilities stem from improper request handling within the application's logic. Defenders should prioritize patching Icinga Web instances to the latest vendor-provided version to mitigate the risk of service interruption and potential data exposure.

Impact

Successful exploitation of these vulnerabilities can lead to a complete loss of availability for the Icinga monitoring system, hindering operational visibility. Additionally, the disclosure of sensitive information can lead to further reconnaissance opportunities for an attacker. These vulnerabilities affect all deployments of Icinga Web where the vulnerable code paths are reachable by remote requests.

Recommendation

  • Apply vendor security patches for CVE-2024-24757 and CVE-2024-24758 immediately across all Icinga Web installations.
  • Audit web server access logs for anomalous request patterns targeting Icinga Web endpoints that result in repeated 5xx status codes, which may indicate attempted DoS exploitation.

Mitigations

Upgrade Icinga Web to the version addressing CVE-2024-24757 and CVE-2024-24758

immediate IT Operations

CVE-2024-24757, CVE-2024-24758