
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6015 is a login MFA rate limit bypass vulnerability in HashiCorp Vault and Vault Enterprise that allows attackers to bypass Multi-Factor Authentication rate limits and reuse Time-based One-Time Password (TOTP) tokens. It affects Vault Community Edition versions 1.10.0 through 1.20.0 and multiple Vault Enterprise version ranges. The vulnerability was published on August 1, 2025, with patches released simultaneously. It carries a CVSS v3.1 base score of 5.7 (Medium) (GitHub Advisory, HashiCorp Advisory).
The root cause is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts), meaning Vault's login MFA subsystem fails to adequately enforce rate limits on authentication attempts. This allows a low-privileged attacker, with some user interaction required, to make repeated MFA validation requests over the network without being throttled, and to reuse previously issued TOTP tokens that should be invalidated after a single use. The attack vector is network-based with low attack complexity, requiring only low-level privileges (GitHub Advisory, HashiCorp Advisory).
Successful exploitation allows an attacker with low-privileged access to circumvent MFA protections on Vault login, potentially gaining unauthorized access to secrets, credentials, and other sensitive data stored in Vault. The CVSS scoring reflects a high confidentiality impact with no integrity or availability impact, meaning the primary risk is unauthorized read access to protected information. Given Vault's role as a secrets management platform, unauthorized access could expose API keys, database credentials, certificates, and other high-value secrets that could enable lateral movement across an organization's infrastructure (GitHub Advisory, HashiCorp Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.028% (0.000280), placing it in a low probability tier for near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
/v1/auth/*/login or /v1/sys/mfa/validate) from a single source IP.HashiCorp has released patched versions that should be applied immediately: Vault Community Edition 1.20.1, and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23 (GitHub Advisory, HashiCorp Advisory). As interim measures, administrators should review and audit recent authentication logs for suspicious MFA activity, implement additional rate-limiting at the network or load balancer level, and enforce strict access controls to limit the blast radius of any compromised accounts. Monitoring for anomalous login patterns is also recommended until patching is complete.
The vulnerability was disclosed by HashiCorp via their security advisory forum (HCSEC-2025-19) on August 1, 2025, with patches released simultaneously, indicating a coordinated disclosure process (HashiCorp Advisory). The advisory was picked up by standard vulnerability tracking services including Vulners, CVEFeed, and security aggregators shortly after publication. No notable independent researcher commentary or significant social media discussion beyond routine CVE tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."