CVE Details
Basic Information
| Title | Vault TOTP Secrets Engine Code Reuse |
|---|---|
| Type | cve |
| Published | 2025-08-01T17:50:09.308Z |
| Modified | 2025-08-01T18:05:37.553Z |
Product Information
| Vendor | HashiCorp |
|---|---|
| Product | Vault |
| Version | 0 |
CVSS Information
| Base Score | 6.5 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Affected Products
- HashiCorp Vault 0
- HashiCorp Vault Enterprise 0
Additional Information
| CWE List | CWE-156 |
|---|---|
| Source | HashiCorp |
Description
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.