<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:degamisu:open-Irs:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adegamisuopen-irs/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 18 Aug 2026 14:50:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adegamisuopen-irs/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in Icinga Web</title><link>https://feed.craftedsignal.io/briefs/2026-08-icinga-vulnerabilities/</link><pubDate>Tue, 18 Aug 2026 14:50:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-icinga-vulnerabilities/</guid><description>Remote attackers can exploit multiple vulnerabilities in Icinga Web to conduct Denial of Service attacks or disclose sensitive information due to improper request handling.</description><content:encoded><![CDATA[<p>Icinga has announced multiple security vulnerabilities (CVE-2024-24757 and CVE-2024-24758) affecting Icinga Web. These flaws allow a remote, unauthenticated attacker to impact the availability of the monitoring interface through Denial of Service (DoS) conditions or gain access to unauthorized information. The vulnerabilities stem from improper request handling within the application's logic. Defenders should prioritize patching Icinga Web instances to the latest vendor-provided version to mitigate the risk of service interruption and potential data exposure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can lead to a complete loss of availability for the Icinga monitoring system, hindering operational visibility. Additionally, the disclosure of sensitive information can lead to further reconnaissance opportunities for an attacker. These vulnerabilities affect all deployments of Icinga Web where the vulnerable code paths are reachable by remote requests.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply vendor security patches for CVE-2024-24757 and CVE-2024-24758 immediately across all Icinga Web installations.</li>
<li>Audit web server access logs for anomalous request patterns targeting Icinga Web endpoints that result in repeated 5xx status codes, which may indicate attempted DoS exploitation.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>webserver</category></item></channel></rss>