MFA Bypass and Token Reuse in HashiCorp Vault and Vault Enterprise
CVE-2025-6015
What is CVE-2025-6015?
The vulnerability in HashiCorp Vault and Vault Enterprise allows attackers to bypass Multi-Factor Authentication (MFA) rate limits, enabling the reuse of Time-based One-Time Password (TOTP) tokens. This flaw poses a serious security risk as it could lead to unauthorized access to sensitive data and systems. The vulnerability affects certain versions of Vault, and users are advised to upgrade to the patched releases to mitigate these risks. For further details, visit the reference link.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Vault 64 bit 1.10.0 < 1.20.1
Vault Enterprise 64 bit 1.10.0 < 1.20.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved