Protection Mechanism Failure in Vault Enterprise and Vault - CVE-2025-6004

 

Protection Mechanism Failure in Vault Enterprise and Vault - CVE-2025-6004

Published: August 6, 2025


Vulnerability identifier: #VU113690
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-6004
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to incorrect implementation of the user lockout mechanism. A remote user can bypass the user lockout feature for Userpass and LDAP authentication methods by varying the cases of characters in the user name when an auth method was not configured to be case sensitive.


Affected software

Vault Enterprise
Vault

How to mitigate CVE-2025-6004

Install updates from vendor's website.

Vault Enterprise - addressed in versions 1.16.23, 1.18.12, 1.19.7, 1.20.1
Vault - update to 1.20.1

External References

Related Security Bulletins