Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects the two-factor authentication process in MISP, allowing a valid code to be used more than once within its validity period. If an attacker can intercept a legitimate code during login, they could potentially use it to gain unauthorized access to a user's account and sensitive threat intelligence data. The main concern is confirming relevance and exposure within your deployed instances.
- Login codes can be reused within seconds.
- Protects sensitive threat intelligence data access.
- Confirm if MISP is deployed and used.
Attack Path
How an attacker could exploit the issue
An attacker could gain unauthorized access to a user's account by intercepting a valid one-time code during a two-factor authentication login. This code, which is typically valid for 30 seconds, could be replayed within its validity window to authenticate a second session. This could lead to the compromise of sensitive threat intelligence data and administrative functions.
- Attacker observes or intercepts a valid TOTP code.
- Replays the code within its validity window.
- Unauthorized account access and data compromise.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, a valid one-time code for two-factor authentication could be reused within its time window, allowing an attacker who intercepts a legitimate code to gain unauthorized access to a user's account. This could potentially expose sensitive threat-intelligence data and administrative functions.
- Account access.
- Code intercepted during login.
- Compromised threat-intelligence data.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in MISP's two-factor authentication requires immediate attention from teams managing the MISP platform and its associated security controls. The first practical step is to identify all instances of MISP, confirm their external reachability and business criticality, and then assign ownership for remediation planning based on the identified risk.
- Assign MISP platform ownership.
- Verify TOTP exposure and reachability.
- Plan and coordinate vendor updates.