This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60425.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References

No reference.

History

Sat, 08 Nov 2025 04:30:00 +0900

Type Values Removed Values Added
Weaknesses CWE-307
CPEs cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.3:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r2:*:*:*:*:*:*
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Sat, 08 Nov 2025 04:15:00 +0900

Type Values Removed Values Added
Title Nagios Fusion < 2024R2.1 2FA Brute Force Bypass
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 08 Nov 2025 03:30:00 +0900

Type Values Removed Values Added
Description Nagios Fusion versions prior to 2024R2.1 contain a brute-force bypass in the Two-Factor Authentication (2FA) implementation. The application did not properly enforce rate limiting or account lockout for repeated failed 2FA verification attempts, allowing a remote attacker to repeatedly try second-factor codes for a targeted account. By abusing the lack of enforcement, an attacker could eventually successfully authenticate to accounts protected by 2FA. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60425.
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Fri, 07 Nov 2025 01:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.3:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r2:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 01 Nov 2025 03:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 19:15:00 +0900

Type Values Removed Values Added
First Time appeared Nagios
Nagios fusion
Vendors & Products Nagios
Nagios fusion

Fri, 31 Oct 2025 06:30:00 +0900

Type Values Removed Values Added
Description Nagios Fusion versions prior to 2024R2.1 contain a brute-force bypass in the Two-Factor Authentication (2FA) implementation. The application did not properly enforce rate limiting or account lockout for repeated failed 2FA verification attempts, allowing a remote attacker to repeatedly try second-factor codes for a targeted account. By abusing the lack of enforcement, an attacker could eventually successfully authenticate to accounts protected by 2FA.
Title Nagios Fusion < 2024R2.1 2FA Brute Force Bypass
Weaknesses CWE-307
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: REJECTED

Assigner: VulnCheck

Published:

Updated: 2025-11-07T18:19:39.010Z

Reserved: 2025-04-15T19:15:22.577Z

Link: CVE-2025-34249

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2025-10-30T22:15:47.260

Modified: 2025-11-07T19:15:47.150

Link: CVE-2025-34249

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-31T19:13:55Z

Weaknesses

No weakness.