Nagios Fusion OTP Verification Rate Limiting Vulnerability Allowing Authentication Bypass

Vulnerability

A vulnerability exists in the OTP verification component of Nagios Fusion versions 2024R1.2 and 2024R2, due to insufficient rate limiting. This flaw allows attackers to perform brute-force attacks on the Two-Factor Authentication (2FA) mechanism, bypassing authentication by repeatedly guessing One-Time Passwords (OTPs). The issue arises from the lack of proper defenses against brute-force attacks, rendering the 2FA implementation ineffective.

Impact

Exploitation of this vulnerability allows attackers to bypass 2FA and gain unauthorized access to accounts, including those of administrators.

Reproduction

To reproduce this vulnerability, log in with a valid username and password. After the system prompts for an OTP, an attacker can send automated requests to the OTP verification endpoint. The absence of rate limiting and account lockout after failed attempts enables unlimited guessing of OTPs, allowing the attacker to predict the correct one and bypass 2FA.

Remediation

Users are advised to update to Nagios Fusion version 2024R2.1, where this vulnerability has been patched.

Added: Oct 27, 2025, 4:19 PM
Updated: Oct 27, 2025, 4:19 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
9.5
remediation
7.7
relevance
0.8
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.