Metrics
Affected Vendors & Products
No reference.
Fri, 07 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:nagios:fusion:2024:r1.0.1:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.0.2:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.0.3:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.1.1:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.1:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r2:*:*:*:*:*:* |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Fri, 07 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Nagios Fusion < R2.1 2FA Lack of Re-Authentication or Session Rotation | |
| Metrics |
ssvc
|
Fri, 07 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nagios Fusion versions prior to R2.1 contain a vulnerability due to the application not requiring re-authentication or session rotation when a user has enabled two-factor authentication (2FA). As a result, an adversary who has obtained a valid session could continue using the active session after the target user enabled 2FA, potentially preventing the legitimate user from locking the attacker out and enabling persistent account takeover. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60424. |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Thu, 06 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.0.1:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.0.2:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.0.3:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.1.1:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.1:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r1:*:*:*:*:*:* cpe:2.3:a:nagios:fusion:2024:r2:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios
Nagios fusion |
|
| Vendors & Products |
Nagios
Nagios fusion |
Thu, 30 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nagios Fusion versions prior to R2.1 contain a vulnerability due to the application not requiring re-authentication or session rotation when a user has enabled two-factor authentication (2FA). As a result, an adversary who has obtained a valid session could continue using the active session after the target user enabled 2FA, potentially preventing the legitimate user from locking the attacker out and enabling persistent account takeover. | |
| Title | Nagios Fusion < R2.1 2FA Lack of Re-Authentication or Session Rotation | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: REJECTED
Assigner: VulnCheck
Published: 2025-10-30T21:19:26.752Z
Updated: 2025-11-07T18:20:15.157Z
Reserved: 2025-04-15T19:15:22.579Z
Link: CVE-2025-34269
Updated:
Status : Rejected
Published: 2025-10-30T22:15:47.393
Modified: 2025-11-07T19:16:13.960
Link: CVE-2025-34269
No data.