CVE-2025-6015

EUVD-2025-23379
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.7 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
hashicorpvault
1.10.0 ≤
𝑥
< 1.16.23
hashicorpvault
1.10.0 ≤
𝑥
< 1.20.1
hashicorpvault
1.17.0 ≤
𝑥
< 1.18.12
hashicorpvault
1.19.0 ≤
𝑥
< 1.19.7
hashicorpvault
1.20.0
𝑥
= Vulnerable software versions