CVE-2025-6004

EUVD-2025-23396
Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
hashicorpvault
1.13.0 ≤
𝑥
< 1.16.23
hashicorpvault
1.13.0 ≤
𝑥
< 1.20.1
hashicorpvault
1.17.0 ≤
𝑥
< 1.18.12
hashicorpvault
1.19.0 ≤
𝑥
< 1.19.7
hashicorpvault
1.20.0
𝑥
= Vulnerable software versions