CVE-2025-6015

Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:1.20.0:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2025-08-01 18:15

Updated : 2025-08-13 18:09


NVD link : CVE-2025-6015

Mitre link : CVE-2025-6015

CVE.ORG link : CVE-2025-6015


JSON object : View

Products Affected

hashicorp

  • vault
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts