CVE-2025-1146 describes a validation logic error in the CrowdStrike Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor. This flaw allows for incorrect processing of server certificate validation during TLS communication with the CrowdStrike cloud. An attacker with network control could exploit this vulnerability to conduct a man-in-the-middle (MiTM) attack, potentially leading to high impact on confidentiality, integrity, and availability. CrowdStrike internally identified and patched this issue in versions 7.06 and above, with no known active exploitation or publicly available exploit code. Community discussion and media coverage are minimal, indicating low external attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CrowdStrike | Falcon Sensor For Linux | >= 7.06, < 7.06.16113, >= 7.07, < 7.07.16209, >= 7.10, < 7.10.16321, >= 7.11, < 7.11.16410, >= 7.13, < 7.13.16606, >= 7.14, < 7.14.16705, >= 7.15, < 7.15.16806, >= 7.16, < 7.16.16909, >= 7.17, < 7.17.17014, >= 7.18, < 7.18.17131, >= 7.19, < 7.19.17221, >= 7.20, < 7.20.17308CNA affecteddefault unknown | |
| CrowdStrike | Falcon Container Sensor | >= 7.06, < 7.06.4705, >= 7.10, < 7.10.4907, >= 7.11, < 7.11.5003, >= 7.12, < 7.12.5102, >= 7.13, < 7.13.5202, >= 7.14, < 7.14.5306, >= 7.15, < 7.15.5403, >= 7.16, < 7.16.5503, >= 7.17, < 7.17.5603, >= 7.18, < 7.18.5705, >= 7.19, < 7.19.5807, >= 7.20, < 7.20.5908CNA affecteddefault unknown | |
| CrowdStrike | Falcon Kubernetes Admission Controller | >= 7.06, < 7.06.603, >= 7.10, < 7.10.806, >= 7.11, < 7.11.904, >= 7.12, < 7.12.1002, >= 7.13, < 7.13.1102, >= 7.14, < 7.14.1203, >= 7.16, < 7.16.1403, >= 7.17, < 7.17.1503, >= 7.18, < 7.18.1605, >= 7.20, < 7.20.1808CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.