PT-2025-31678 · Hashicorp+2 · Vault Enterprise+3
Yarden Porat
·
Published
2025-08-01
·
Updated
2025-10-01
·
CVE-2025-6004
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Vault versions prior to 1.20.1
Vault Enterprise versions prior to 1.20.1, 1.19.7, 1.18.12, and 1.16.23
Description
The user lockout feature in Vault and Vault Enterprise could be bypassed for Userpass and LDAP authentication methods.
Recommendations
Update to Vault Community Edition version 1.20.1 or later.
Update to Vault Enterprise version 1.20.1, 1.19.7, 1.18.12, or 1.16.23 or later.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Red Os
Vault
Vault Enterprise