Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-215101
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 06:48
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T06:48:09.325269+00:00",
"id": "EUVD-2026-215101"
}
CVE-2025-1146 (GCVE-0-2025-1146)
Vulnerability from cvelistv5 – Published: 2025-02-12 18:27 – Updated: 2025-02-12 19:40
VLAI
EPSS
VEX
Title
CrowdStrike Falcon Sensor for Linux TLS Issue
Summary
CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection routine to the CrowdStrike cloud can incorrectly process server certificate validation. This could allow an attacker with the ability to control network traffic to potentially conduct a man-in-the-middle (MiTM) attack. CrowdStrike identified this issue internally and released a security fix in all Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor versions 7.06 and above.
CrowdStrike identified this issue through our longstanding, rigorous security review process, which has been continually strengthened with deeper source code analysis and ongoing program enhancements as part of our commitment to security resilience. CrowdStrike has no indication of any exploitation of this issue in the wild. CrowdStrike has leveraged its world class threat hunting and intelligence capabilities to actively monitor for signs of abuse or usage of this flaw and will continue to do so.
Windows and Mac sensors are not affected by this.
Severity
8.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-02-12 19:40 UTC
CWE
- CWE-296 - Improper Following of a Certificate's Chain of Trust
Assigner
References
1 reference
Impacted products
3 products
| Vendor | Product | Version | |
|---|---|---|---|
| CrowdStrike | Falcon sensor for Linux |
Unaffected:
7.21.17405
(semver)
Affected: 7.20 , < 7.20.17308 (semver) Affected: 7.19 , < 7.19.17221 (semver) Affected: 7.18 , < 7.18.17131 (semver) Affected: 7.17 , < 7.17.17014 (semver) Affected: 7.16 , < 7.16.16909 (semver) Affected: 7.15 , < 7.15.16806 (semver) Affected: 7.14 , < 7.14.16705 (semver) Affected: 7.13 , < 7.13.16606 (semver) Affected: 7.11 , < 7.11.16410 (semver) Affected: 7.10 , < 7.10.16321 (semver) Affected: 7.07 , < 7.07.16209 (semver) Affected: 7.06 , < 7.06.16113 (semver) |
|
| CrowdStrike | Falcon Kubernetes Admission Controller |
Unaffected:
7.21.1904
(semver)
Affected: 7.20 , < 7.20.1808 (semver) Affected: 7.18 , < 7.18.1605 (semver) Affected: 7.17 , < 7.17.1503 (semver) Affected: 7.16 , < 7.16.1403 (semver) Affected: 7.14 , < 7.14.1203 (semver) Affected: 7.13 , < 7.13.1102 (semver) Affected: 7.12 , < 7.12.1002 (semver) Affected: 7.11 , < 7.11.904 (semver) Affected: 7.10 , < 7.10.806 (semver) Affected: 7.06 , < 7.06.603 (semver) |
|
| CrowdStrike | Falcon Container Sensor |
Unaffected:
7.21.6003
(semver)
Affected: 7.20 , < 7.20.5908 (semver) Affected: 7.19 , < 7.19.5807 (semver) Affected: 7.18 , < 7.18.5705 (semver) Affected: 7.17 , < 7.17.5603 (semver) Affected: 7.16 , < 7.16.5503 (semver) Affected: 7.15 , < 7.15.5403 (semver) Affected: 7.14 , < 7.14.5306 (semver) Affected: 7.13 , < 7.13.5202 (semver) Affected: 7.12 , < 7.12.5102 (semver) Affected: 7.11 , < 7.11.5003 (semver) Affected: 7.10 , < 7.10.4907 (semver) Affected: 7.06 , < 7.06.4705 (semver) |
Date Public
2025-02-12 18:27
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-1146",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-02-12T19:40:26.132160Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-02-12T19:40:41.867Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"packageName": "falcon-sensor",
"platforms": [
"Linux"
],
"product": "Falcon sensor for Linux",
"vendor": "CrowdStrike",
"versions": [
{
"status": "unaffected",
"version": "7.21.17405",
"versionType": "semver"
},
{
"lessThan": "7.20.17308",
"status": "affected",
"version": "7.20",
"versionType": "semver"
},
{
"lessThan": "7.19.17221",
"status": "affected",
"version": "7.19",
"versionType": "semver"
},
{
"lessThan": "7.18.17131",
"status": "affected",
"version": "7.18",
"versionType": "semver"
},
{
"lessThan": "7.17.17014",
"status": "affected",
"version": "7.17",
"versionType": "semver"
},
{
"lessThan": "7.16.16909",
"status": "affected",
"version": "7.16",
"versionType": "semver"
},
{
"lessThan": "7.15.16806",
"status": "affected",
"version": "7.15",
"versionType": "semver"
},
{
"lessThan": "7.14.16705",
"status": "affected",
"version": "7.14",
"versionType": "semver"
},
{
"lessThan": "7.13.16606",
"status": "affected",
"version": "7.13",
"versionType": "semver"
},
{
"lessThan": "7.11.16410",
"status": "affected",
"version": "7.11",
"versionType": "semver"
},
{
"lessThan": "7.10.16321",
"status": "affected",
"version": "7.10",
"versionType": "semver"
},
{
"lessThan": "7.07.16209",
"status": "affected",
"version": "7.07",
"versionType": "semver"
},
{
"lessThan": "7.06.16113",
"status": "affected",
"version": "7.06",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unknown",
"platforms": [
"Linux"
],
"product": "Falcon Kubernetes Admission Controller",
"vendor": "CrowdStrike",
"versions": [
{
"status": "unaffected",
"version": "7.21.1904",
"versionType": "semver"
},
{
"lessThan": "7.20.1808",
"status": "affected",
"version": "7.20",
"versionType": "semver"
},
{
"lessThan": "7.18.1605",
"status": "affected",
"version": "7.18",
"versionType": "semver"
},
{
"lessThan": "7.17.1503",
"status": "affected",
"version": "7.17",
"versionType": "semver"
},
{
"lessThan": "7.16.1403",
"status": "affected",
"version": "7.16",
"versionType": "semver"
},
{
"lessThan": "7.14.1203",
"status": "affected",
"version": "7.14",
"versionType": "semver"
},
{
"lessThan": "7.13.1102",
"status": "affected",
"version": "7.13",
"versionType": "semver"
},
{
"lessThan": "7.12.1002",
"status": "affected",
"version": "7.12",
"versionType": "semver"
},
{
"lessThan": "7.11.904",
"status": "affected",
"version": "7.11",
"versionType": "semver"
},
{
"lessThan": "7.10.806",
"status": "affected",
"version": "7.10",
"versionType": "semver"
},
{
"lessThan": "7.06.603",
"status": "affected",
"version": "7.06",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unknown",
"platforms": [
"Linux"
],
"product": "Falcon Container Sensor",
"vendor": "CrowdStrike",
"versions": [
{
"status": "unaffected",
"version": "7.21.6003",
"versionType": "semver"
},
{
"lessThan": "7.20.5908",
"status": "affected",
"version": "7.20",
"versionType": "semver"
},
{
"lessThan": "7.19.5807",
"status": "affected",
"version": "7.19",
"versionType": "semver"
},
{
"lessThan": "7.18.5705",
"status": "affected",
"version": "7.18",
"versionType": "semver"
},
{
"lessThan": "7.17.5603",
"status": "affected",
"version": "7.17",
"versionType": "semver"
},
{
"lessThan": "7.16.5503",
"status": "affected",
"version": "7.16",
"versionType": "semver"
},
{
"lessThan": "7.15.5403",
"status": "affected",
"version": "7.15",
"versionType": "semver"
},
{
"lessThan": "7.14.5306",
"status": "affected",
"version": "7.14",
"versionType": "semver"
},
{
"lessThan": "7.13.5202",
"status": "affected",
"version": "7.13",
"versionType": "semver"
},
{
"lessThan": "7.12.5102",
"status": "affected",
"version": "7.12",
"versionType": "semver"
},
{
"lessThan": "7.11.5003",
"status": "affected",
"version": "7.11",
"versionType": "semver"
},
{
"lessThan": "7.10.4907",
"status": "affected",
"version": "7.10",
"versionType": "semver"
},
{
"lessThan": "7.06.4705",
"status": "affected",
"version": "7.06",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.20.17308",
"versionStartIncluding": "7.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.19.17221",
"versionStartIncluding": "7.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.18.17131",
"versionStartIncluding": "7.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.17.17014",
"versionStartIncluding": "7.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.16.16909",
"versionStartIncluding": "7.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.15.16806",
"versionStartIncluding": "7.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.14.16705",
"versionStartIncluding": "7.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.13.16606",
"versionStartIncluding": "7.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.11.16410",
"versionStartIncluding": "7.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.10.16321",
"versionStartIncluding": "7.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.07.16209",
"versionStartIncluding": "7.07",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:crowdstrike:falcon:*:*:*:*:*:linux:*:*",
"versionEndExcluding": "7.06.16113",
"versionStartIncluding": "7.06",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"datePublic": "2025-02-12T18:27:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection routine to the CrowdStrike cloud can incorrectly process server certificate validation. This could allow an attacker with the ability to control network traffic to potentially conduct a man-in-the-middle (MiTM) attack. CrowdStrike identified this issue internally and released a security fix in all Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor versions 7.06 and above.\u003cbr\u003e\u003cbr\u003e \u003cbr\u003eCrowdStrike identified this issue through our longstanding, rigorous security review process, which has been continually strengthened with deeper source code analysis and ongoing program enhancements as part of our commitment to security resilience. CrowdStrike has no indication of any exploitation of this issue in the wild. CrowdStrike has leveraged its world class threat hunting and intelligence capabilities to actively monitor for signs of abuse or usage of this flaw and will continue to do so. \u003cbr\u003e\u003cbr\u003e\u003cbr\u003eWindows and Mac sensors are not affected by this.\u003cbr\u003e\u003cbr\u003e"
}
],
"value": "CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection routine to the CrowdStrike cloud can incorrectly process server certificate validation. This could allow an attacker with the ability to control network traffic to potentially conduct a man-in-the-middle (MiTM) attack. CrowdStrike identified this issue internally and released a security fix in all Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor versions 7.06 and above.\n\n \nCrowdStrike identified this issue through our longstanding, rigorous security review process, which has been continually strengthened with deeper source code analysis and ongoing program enhancements as part of our commitment to security resilience. CrowdStrike has no indication of any exploitation of this issue in the wild. CrowdStrike has leveraged its world class threat hunting and intelligence capabilities to actively monitor for signs of abuse or usage of this flaw and will continue to do so. \n\n\nWindows and Mac sensors are not affected by this."
}
],
"impacts": [
{
"capecId": "CAPEC-94",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-94 Adversary in the Middle (AiTM)"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-296",
"description": "CWE-296: Improper Following of a Certificate\u0027s Chain of Trust",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-02-12T18:48:50.205Z",
"orgId": "13ddcd98-6f4a-40a8-8e24-29ca0aee4661",
"shortName": "CrowdStrike"
},
"references": [
{
"url": "https://www.crowdstrike.com/security-advisories/cve-2025-1146/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "CrowdStrike Falcon Sensor for Linux TLS Issue",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "13ddcd98-6f4a-40a8-8e24-29ca0aee4661",
"assignerShortName": "CrowdStrike",
"cveId": "CVE-2025-1146",
"datePublished": "2025-02-12T18:27:35.458Z",
"dateReserved": "2025-02-10T03:03:51.392Z",
"dateUpdated": "2025-02-12T19:40:41.867Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…