Improper authentication in Vault Enterprise and Vault - CVE-2025-6014

 

Improper authentication in Vault Enterprise and Vault - CVE-2025-6014

Published: August 6, 2025


Vulnerability identifier: #VU113692
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-6014
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass TOTP authentication.

The vulnerability exists due to used code entries in the TOTP used code cache were not normalized, making it possible to reuse existing codes by appending whitespace. A remote user with knowledge of existing user credentials can bypass TOTP authentication. 


Affected software

Vault Enterprise
Vault

How to mitigate CVE-2025-6014

Install updates from vendor's website.

Vault Enterprise - addressed in versions 1.16.23, 1.18.12, 1.19.7, 1.20.1
Vault - update to 1.20.1

External References

Related Security Bulletins