Airship AI Acropolis MFA insufficient rate limiting
Vulnerability Description
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-35041
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Zach Crosman, CISA
References
More from Airship AI
View All →Affected Vendor
Airship AI
View all reports →