Impact
MISP’s OTP flow contains a flaw where the OTP verification logic compares the submitted HOTP token against a counter value stored in the user’s session rather than the authoritative counter in the database. Because the cached counter is not refreshed after a token is successfully used, an attacker who manages to retain a valid session in which the password prompt has already been satisfied can replay the same HOTP token. The stale cached counter still matches the replayed token, allowing a second successful authentication and effectively rewinding the counter, which can corrupt future token validation and enable further replays. The security impact is a bypass of the second‑factor authentication, giving an attacker unauthorized access to the victim’s MISP account and potentially invalidating subsequent legitimate HOTP tokens.
Affected Systems
The vulnerability affects MISP software version 2.5.48 and earlier. All users of older MISP releases that have HOTP (paper token) second‑factor authentication enabled are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates moderate severity, and the EPSS score is not available, suggesting insufficient data on active exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker already holds a valid authenticated session with the password step completed but the OTP step pending, or that the attacker obtains a session cookie through other compromise. Once the session is established, replaying a held HOTP token is straightforward. It is inferred that the risk may be higher in environments that keep sessions alive for extended periods or do not invalidate session data on logout, but this observation is not explicitly stated in the CVE description. The official CNA fix replaces the session‑cached counter with an authoritative database read protected by a Redis‑based distributed lock, increments the counter atomically, and deletes the cached session entry after successful authentication, preventing the replay.
OpenCVE Enrichment