CVE-2025-34249
30.10.2025, 22:15
Nagios Fusion versions prior to 2024R2.1contain a brute-force bypass in the Two-Factor Authentication (2FA) implementation. The application did not properly enforce rate limiting or account lockout for repeated failed 2FA verification attempts, allowing a remote attacker to repeatedly try second-factor codes for a targeted account. By abusing the lack of enforcement, an attacker could eventually successfully authenticate to accounts protected by 2FA.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.