MFA Improper Limitation of a Record Access in Airship AI Acropolis
CVE-2025-35041

7.7HIGH

Key Information:

Vendor

Airship Ai

Status
Vendor
CVE Published:
22 September 2025

What is CVE-2025-35041?

The Airship AI Acropolis product is vulnerable due to a flaw in its multi-factor authentication (MFA) mechanism. Specifically, after a user successfully logs in with valid credentials, the system allows unlimited attempts to enter the MFA code for a 15-minute period. This vulnerability enables remote attackers who already possess valid user credentials to conduct brute-force attacks on the 6-digit MFA code, potentially compromising user accounts. The issue has been addressed in the versions 10.2.35, 11.0.21, and 11.1.9.

Affected Version(s)

Acropolis 0 < 10.2.35

Acropolis 0 < 11.0.21

Acropolis 0 < 11.1.9

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zach Crosman, CISA
.
CVE-2025-35041 : MFA Improper Limitation of a Record Access in Airship AI Acropolis