PT-2025-44461 · Unknown · Nagios Fusion

Published

2025-10-30

·

Updated

2025-10-31

·

CVE-2025-34249

CVSS v4.0
10
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nagios Fusion versions prior to 2024R2.1
Description The application lacks proper rate limiting or account lockout mechanisms for repeated failed Two-Factor Authentication (2FA) verification attempts. This allows a remote attacker to repeatedly guess second-factor codes for a targeted account. By exploiting this deficiency, an attacker could potentially bypass 2FA and successfully authenticate to accounts protected by it.
Recommendations Update to version 2024R2.1 or later.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

BDU:2025-15971
CVE-2025-34249

Affected Products

Nagios Fusion