CVE-2025-6015
Vault Login MFA Bypass of Rate Limiting and TOTP Code Reuse
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.7EPSS 0.3%KEV nãoPoC —Patch —
Lifecycle
01 Aug 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →