Impact
MISP implements throttling of authentication-failure log entries with a Redis key. The code only logs a failure when Redis is reachable and no throttle key is present. If the Redis connection cannot be established, the function silently suppresses every authentication-failure event. This loss of logging (CWE-778) weakens the visibility of authentication failures, undermining the ability to detect brute-force or credential-theft activity.
Affected Systems
Affected versions are all releases of the MISP platform up to and including 2.5.45. The issue resides in the MISP application provided by the vendor MISP: MISP. Administrators using these versions are at risk until the application is upgraded.
Risk and Exploitability
The CVSS score is 5.1, indicating moderate severity. The EPSS score is less than 1%, indicating a low probability; it is not listed in the CISA KEV catalog. Exploitation requires an attacker to disrupt or otherwise make unavailable the Redis service used by MISP for throttling. The effect is suppression of authentication-failure logging, which limits audit visibility but does not provide code execution or compromise of confidentiality. Organizations should consider the moderate risk, particularly if a Redis outage occurs.
OpenCVE Enrichment