PT-2025-25341 · Vantage6 · Vantage6
Bartvanb
·
Published
2025-06-12
·
Updated
2025-09-17
·
CVE-2025-43863
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vantage6 versions prior to 4.11
Description
The issue concerns an open-source framework designed for privacy-enhancing technologies such as Federated Learning and Multi-Party Computation. If an attacker gains access to an authenticated session, they can exploit the change password functionality to brute-force the user password. This is possible because the change password route can be called infinitely, providing feedback on incorrect passwords until the correct one is entered.
Recommendations
For versions prior to 4.11, update to version 4.11 to resolve the issue.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vantage6