CVE Vulnerabilities

CVE-2025-60424

Improper Authentication

Published: Oct 27, 2025 | Modified: Nov 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Fusion Nagios 2024-r1.2 (including) 2024-r1.2 (including)
Fusion Nagios 2024-r2.1 (including) 2024-r2.1 (including)

Potential Mitigations

References