This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60424.
References

No reference.

History

Fri, 07 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-613
CPEs cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.3:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r2:*:*:*:*:*:*
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Fri, 07 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Title Nagios Fusion < R2.1 2FA Lack of Re-Authentication or Session Rotation
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
Description Nagios Fusion versions prior to R2.1 contain a vulnerability due to the application not requiring re-authentication or session rotation when a user has enabled two-factor authentication (2FA). As a result, an adversary who has obtained a valid session could continue using the active session after the target user enabled 2FA, potentially preventing the legitimate user from locking the attacker out and enabling persistent account takeover. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60424.
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Thu, 06 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.0.3:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r1:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r2:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Fri, 31 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios fusion
Vendors & Products Nagios
Nagios fusion

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios Fusion versions prior to R2.1 contain a vulnerability due to the application not requiring re-authentication or session rotation when a user has enabled two-factor authentication (2FA). As a result, an adversary who has obtained a valid session could continue using the active session after the target user enabled 2FA, potentially preventing the legitimate user from locking the attacker out and enabling persistent account takeover.
Title Nagios Fusion < R2.1 2FA Lack of Re-Authentication or Session Rotation
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: REJECTED

Assigner: VulnCheck

Published: 2025-10-30T21:19:26.752Z

Updated: 2025-11-07T18:20:15.157Z

Reserved: 2025-04-15T19:15:22.579Z

Link: CVE-2025-34269

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2025-10-30T22:15:47.393

Modified: 2025-11-07T19:16:13.960

Link: CVE-2025-34269

cve-icon Redhat

No data.