CVE-2025-6011
Timing Side-Channel in Vault’s Userpass Auth Method
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Un canal lateral de temporización en el método de autenticación por contraseña de usuario de Vault y Vault Enterprise (Vault) permitía a un atacante distinguir entre usuarios existentes y no existentes, y potencialmente enumerar nombres de usuario válidos para el método de autenticación por contraseña de Vault. Corregido en Vault Community Edition 1.20.1 y Vault Enterprise 1.20.1, 1.19.7, 1.18.12 y 1.16.23.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-06-11 CVE Reserved
- 2025-08-01 CVE Published
- 2025-08-04 CVE Updated
- 2025-08-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
CAPEC
- CAPEC description not found.
References (1)
URL | Tag | Source |
---|---|---|
https://discuss.hashicorp.com/t/hcsec-2025-15-timing-side-channel-in-vault-s-userpass-auth-method/76034 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
HashiCorp Search vendor "HashiCorp" | Vault Search vendor "HashiCorp" for product "Vault" | < 1.20.1 Search vendor "HashiCorp" for product "Vault" and version " < 1.20.1" | en |
Affected
| ||||||
HashiCorp Search vendor "HashiCorp" | Vault Enterprise Search vendor "HashiCorp" for product "Vault Enterprise" | < 1.20.1 Search vendor "HashiCorp" for product "Vault Enterprise" and version " < 1.20.1" | en |
Affected
|