CVE-2025-60425

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/10/2025
Last modified:
05/11/2025

Description

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:*
cpe:2.3:a:nagios:fusion:2024:r2.1:*:*:*:*:*:*