Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server's certificate despite a certificate authority being specified. Icinga 2 instances which connect to any of the mentioned time series databases (TSDBs) using TLS over a spoofable infrastructure should immediately upgrade to version 2.13.1, 2.12.6, or 2.11.11 to patch the issue. Such instances should also change the credentials (if any) used by the TSDB writer feature to authenticate against the TSDB. There are no workarounds aside from upgrading.
Conclusion & alert: CVE-2021-37698 is rated Moderate Risk (55.5/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.42%). Core evidence: EPSS rose +1.26% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.17% | 1.42% | +1.26% |
| 2 | 2026-01-14 | 0.14% | 0.17% | +0.03% |
| 3 | 2026-01-08 | — | 0.14% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2021-37698: 1 source package rows (icinga2); 7 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 0. | https://security.alpinelinux.org/vuln/CVE-2021-37698 |
debian
|
not yet assigned | CVE-2021-37698 not yet assigned priority: Debian including 1 source packages (icinga2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-37698 |
gentoo
|
low | CVE-2021-37698: 1 GLSA(s) (202412-08), 1 atom(s) (net-analyzer/icinga2); latest impact low. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2021-37698 |
suse
|
medium | CVE-2021-37698 severity moderate: SUSE including 17 source package names (icinga, icinga2-2.13.1-1.3, …), 18 product×package rows across 4 product lines (SUSE Linux Enterprise Module for HPC 12, SUSE Manager Client Tools Beta for SLE 12, SUSE Manager Client Tools for SLE 12, openSUSE Tumbleweed): Fixed 16, Known Not Affected 2. | https://www.suse.com/security/cve/CVE-2021-37698/ |
ubuntu
|
medium | CVE-2021-37698 medium priority: Ubuntu including 1 source packages (icinga2), 15 status rows across 15 suites (bionic, focal, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 6, needs-triage 4, ignored 3, DNE 1, released 1. | https://ubuntu.com/security/CVE-2021-37698 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| icinga | icinga | >= 2.5.0, < 2.11.10 | cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:* |
| icinga | icinga | >= 2.12.0, < 2.12.6 | cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:* |
| icinga | icinga | >= 2.13.0, < 2.13.1 | cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/Icinga/icinga2/releases/tag/v2.11.11 | Release Notes Third Party Advisory |
| https://github.com/Icinga/icinga2/releases/tag/v2.12.6 | Release Notes Third Party Advisory |
| https://github.com/Icinga/icinga2/releases/tag/v2.13.1 | Release Notes Third Party Advisory |
| https://github.com/Icinga/icinga2/security/advisories/GHSA-cxfm-8j5v-5qr2 | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2021/11/msg00010.html | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2024/11/msg00010.html |