MFA Bypass and Token Reuse in HashiCorp Vault and Vault Enterprise
CVE-2025-6015

5.7MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
1 August 2025

What is CVE-2025-6015?

The vulnerability in HashiCorp Vault and Vault Enterprise allows attackers to bypass Multi-Factor Authentication (MFA) rate limits, enabling the reuse of Time-based One-Time Password (TOTP) tokens. This flaw poses a serious security risk as it could lead to unauthorized access to sensitive data and systems. The vulnerability affects certain versions of Vault, and users are advised to upgrade to the patched releases to mitigate these risks. For further details, visit the reference link.

Affected Version(s)

Vault 64 bit 1.10.0 < 1.20.1

Vault Enterprise 64 bit 1.10.0 < 1.20.1

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.