Exploitation Summary
EIP tracks 2 public exploits for CVE-2025-60424. PoCs published by adminlove520, aakashtyal.
AI-analyzed exploit summary The repository contains a scanner for CVE-2024-21762, which checks for the presence of the vulnerability in Fortinet SSL VPN interfaces. It includes Python scripts that send crafted HTTP requests to detect if a host is vulnerable.
Description
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.
Exploits (2)
The repository contains a scanner for CVE-2024-21762, which checks for the presence of the vulnerability in Fortinet SSL VPN interfaces. It includes Python scripts that send crafted HTTP requests to detect if a host is vulnerable.
This repository contains a detailed writeup describing a brute-force vulnerability in Nagios Fusion's 2FA implementation (CVE-2025-60424), highlighting the lack of rate-limiting and account lockout mechanisms. It explains the attack vector and mitigation strategies but does not include exploit code.
References (3)
Scores
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L