CVE-2025-34249: Nagios Fusion < 2024R2.1 2FA Brute Force Bypass
Published Oct 30, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60425.
Affected Software
10 affected components
Nagios Fusion<2024R2.1
Nagios Fusion<=4.2.0
Nagios Fusion=2024-r1
Nagios Fusion=2024-r1.0.1
Nagios Fusion=2024-r1.0.2
Nagios Fusion=2024-r1.0.3
Nagios Fusion=2024-r1.1
Nagios Fusion=2024-r1.1.1
Nagios Fusion=2024-r1.2
Nagios Fusion=2024-r2
Remediation
Information
Nagios addresses this vulnerability as "Brute force bypass possible when using Two-Factor Authentication (2FA)" and "Added account lockout if too many failed two-factor authentication attempts are made."
Event History
Oct 30, 2025
CVE Published
via MITRE·09:19 PM
Rejected
via MITRE·09:19 PM
Data Sourced
via NVD·10:15 PM
Description
Nov 7, 2025
Rejected
via MITRE·06:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-34249?
CVE-2025-34249 is classified as a high severity vulnerability due to the potential for unauthorized access through brute-force attacks.
2
How do I fix CVE-2025-34249?
To resolve CVE-2025-34249, upgrade to Nagios Fusion version 2024R2.1 or later.
3
What type of attack does CVE-2025-34249 facilitate?
CVE-2025-34249 facilitates brute-force attacks against the Two-Factor Authentication feature.
4
What are the implications of CVE-2025-34249 for users?
Users of Nagios Fusion prior to version 2024R2.1 are at risk of account compromise due to ineffective rate limiting on 2FA attempts.
5
Is CVE-2025-34249 a remote or local vulnerability?
CVE-2025-34249 is a remote vulnerability, allowing attackers to exploit the weakness without physical access to the system.