CVE-2025-35041
7.5Airship AI · Acropolis
Airship AI Acropolis fails to rate-limit multi-factor authentication attempts, allowing remote attackers with valid credentials to brute-force MFA codes for a fifteen-minute window.
Executive summary
A vulnerability in Airship AI Acropolis permits unlimited MFA attempts, enabling attackers with valid credentials to bypass security protections via brute-force attacks.
Vulnerability
This is an improper restriction of excessive authentication attempts (CWE-307) that allows an authenticated user to perform unlimited MFA verification attempts for 15 minutes.
Business impact
The inability to rate-limit MFA attempts significantly lowers the security efficacy of multi-factor authentication, which is a critical defense against credential compromise. Given the CVSS score of 7.5, this high-severity flaw enables an attacker who has obtained primary credentials to gain unauthorized access to sensitive systems or data. Failure to remediate could lead to full account takeover, resulting in severe data loss or unauthorized administrative access within the Acropolis environment.
Remediation
Immediate Action: Update Airship AI Acropolis to version 10.2.35, 11.0.21, 11.1.9, or later to enforce proper MFA rate limiting.
Proactive Monitoring: Review authentication logs specifically for high volumes of MFA failures originating from single user accounts or suspicious IP addresses.
Compensating Controls: While no direct virtual patch is available, ensure that account lockout policies are strictly enforced for primary credentials to prevent the initial authentication phase from being compromised.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant lapse in authentication security that effectively neuters multi-factor protection. Administrators must prioritize the application of the provided security updates across all affected Acropolis instances immediately to restore the integrity of the login process and prevent unauthorized access.
More Airship AI CVEs
Sources
Originally found and disclosed by Zach Crosman, CISA, per the CVE Program record.