CVE-2025-60424 Details
Description
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.
A vulnerability exists in the OTP verification component of Nagios Fusion versions 2024R1.2 and 2024R2, due to insufficient rate limiting. This flaw allows attackers to perform brute-force attacks on the Two-Factor Authentication (2FA) mechanism, bypassing authentication by repeatedly guessing One-Time Passwords (OTPs). The issue arises from the lack of proper defenses against brute-force attacks, rendering the 2FA implementation ineffective.
Users are advised to update to Nagios Fusion version 2024R2.1, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aakashtyal/2FA-Bypass-using-a-Brute-Force-Attack | [email protected] | MitigationThird Party Advisory |
| https://github.com/aakashtyal/2FA-Bypass-using-a-Brute-Force-Attack-CVE-2025-60424 | [email protected] | MitigationThird Party Advisory |
| https://www.nagios.com/changelog/#fusion | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nagios fusion | 2024 r1.2 2024 r2.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 5, 2025 | Initial Analysis | [email protected] |
| Oct 27, 2025 | New CVE Received | [email protected] |
| Oct 27, 2025 | CVE Modified | CISA-ADP |