Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30815 | Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9. |
Fri, 19 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Airship.ai
Airship.ai acropolis |
|
| CPEs | cpe:2.3:a:airship.ai:acropolis:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Airship.ai
Airship.ai acropolis |
Tue, 30 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Airship Ai
Airship Ai acropolis |
|
| Vendors & Products |
Airship Ai
Airship Ai acropolis |
Mon, 22 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9. | |
| Title | Airship AI Acropolis MFA insufficient rate limiting | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-09-30T16:46:22.643Z
Reserved: 2025-04-15T20:56:24.405Z
Link: CVE-2025-35041
Updated: 2025-09-30T16:46:16.620Z
Status : Analyzed
Published: 2025-09-22T16:15:42.720
Modified: 2025-12-19T12:30:13.207
Link: CVE-2025-35041
No data.
OpenCVE Enrichment
Updated: 2025-09-23T16:09:11Z
EUVD