Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HHIGH: 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unknown
Any version before 10.2.35
affected
Any version before 11.0.21
affected
Any version before 11.1.9
affected
10.2.35
unaffected
11.0.21
unaffected
11.1.9
unaffected
Description
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
Any version before 10.2.35
Any version before 11.0.21
Any version before 11.1.9
10.2.35
11.0.21
11.1.9
Credits
Zach Crosman, CISA
References
www.cve.org/CVERecord?id=CVE-2025-35041 (url)
raw.githubusercontent.com/...IT/white/2025/va-25-265-01.json (url)