Impact
MISP's two‑factor authentication process was found to allow the same TOTP code to be used more than once within its time window. The vulnerability is caused by the absence of a record of a consumed TOTP period, so a code remains valid for the entire 30‑second window. An attacker who captures a legitimate code during a user's login can replay it, enabling unauthorized access to the victim’s account and the data or administrative functions protected by that account.
Affected Systems
The flaw affects all MISP installations that use two‑factor authentication and run a version older than 2.5.48. The affected product is the MISP platform itself, and the vulnerability is present in any deployed instance before the vendor released the patch that introduces a single‑use enforcement mechanism.
Risk and Exploitability
The criticality of the vulnerability is reflected in a 9.3 CVSS score, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the weakness by observing or intercepting a TOTP code during a legitimate authentication – either through network‑level eavesdropping, shoulder surfing, or a compromised client – and then replaying that code before the 30‑second validity period expires. Because the vulnerability requires the target user to have two‑factor enabled, the attack surface is limited to those accounts, but once an attacker succeeds, they gain full access to two‑factor authenticated sessions.
OpenCVE Enrichment