Description
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.
Published: 2025-09-22
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30815 Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.
History

Fri, 19 Dec 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Airship.ai
Airship.ai acropolis
CPEs cpe:2.3:a:airship.ai:acropolis:*:*:*:*:*:*:*:*
Vendors & Products Airship.ai
Airship.ai acropolis

Tue, 30 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Airship Ai
Airship Ai acropolis
Vendors & Products Airship Ai
Airship Ai acropolis

Mon, 22 Sep 2025 16:00:00 +0000

Type Values Removed Values Added
Description Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.
Title Airship AI Acropolis MFA insufficient rate limiting
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Airship.ai Acropolis
Airship Ai Acropolis
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2025-09-30T16:46:22.643Z

Reserved: 2025-04-15T20:56:24.405Z

Link: CVE-2025-35041

cve-icon Vulnrichment

Updated: 2025-09-30T16:46:16.620Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-22T16:15:42.720

Modified: 2025-12-19T12:30:13.207

Link: CVE-2025-35041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-23T16:09:11Z

Weaknesses