Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23379 | Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability |
Github GHSA |
GHSA-v6r4-35f9-9rpw | Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:vault:1.20.0:*:*:*:enterprise:*:*:* |
Mon, 04 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 04 Aug 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
|
| Vendors & Products |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
Fri, 01 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23. | |
| Title | Vault Login MFA Bypass of Rate Limiting and TOTP Code Reuse | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-08-01T18:35:17.893Z
Reserved: 2025-06-11T19:05:27.750Z
Link: CVE-2025-6015
Updated: 2025-08-01T18:35:11.034Z
Status : Analyzed
Published: 2025-08-01T18:15:57.010
Modified: 2025-08-13T18:09:08.700
Link: CVE-2025-6015
OpenCVE Enrichment
Updated: 2025-08-04T08:58:49Z
EUVD
Github GHSA