« Volver al listado

CVE-2023-25000

Estado: ModificadaMedia (4.7)—

HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-25000",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-25000",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-12T15:02:13.804694Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@hashicorp.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 0.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "security@hashicorp.com",
      "affectedData": [
        {
          "repo": "https://github.com/hashicorp/vault",
          "vendor": "HashiCorp",
          "product": "Vault",
          "versions": [
            {
              "status": "affected",
              "version": "1.13.0",
              "lessThan": "1.13.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.12.0",
              "lessThan": "1.12.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.11.0",
              "lessThan": "1.11.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.11.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Windows",
            "MacOS",
            "Linux",
            "x86",
            "ARM",
            "64 bit",
            "32 bit"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "HashiCorp",
          "product": "Vault Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "1.13.0",
              "lessThan": "1.13.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.12.0",
              "lessThan": "1.12.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.11.0",
              "lessThan": "1.11.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.11.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Windows",
            "MacOS",
            "Linux",
            "x86",
            "ARM",
            "64 bit",
            "32 bit"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-03-30T01:15:07.493",
  "references": [
    {
      "url": "https://discuss.hashicorp.com/t/hcsec-2023-10-vault-vulnerable-to-cache-timing-attacks-during-seal-and-unseal-operations/52078",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@hashicorp.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20230526-0008/",
      "source": "security@hashicorp.com"
    },
    {
      "url": "https://discuss.hashicorp.com/t/hcsec-2023-10-vault-vulnerable-to-cache-timing-attacks-during-seal-and-unseal-operations/52078",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20230526-0008/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@hashicorp.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-208"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-203"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9."
    }
  ],
  "lastModified": "2026-06-17T05:40:27.210",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C565DBD-95F4-4951-A029-93ABE5315740",
              "versionEndExcluding": "1.11.9"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80EB9F32-09A4-469C-AF76-1AE3137EAC1B",
              "versionEndExcluding": "1.11.9"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "446F872F-F64C-44CA-85BC-144FCFBCFA8B",
              "versionEndExcluding": "1.12.5",
              "versionStartIncluding": "1.12.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71A02FE6-C8D4-455D-A71A-C8353E1ECB7C",
              "versionEndExcluding": "1.12.5",
              "versionStartIncluding": "1.12.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81280166-3DF7-4867-95E9-A7AFB9A12CE7",
              "versionEndExcluding": "1.13.1",
              "versionStartIncluding": "1.13.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C56E203C-1E18-4395-B500-B6EA695B16C0",
              "versionEndExcluding": "1.13.1",
              "versionStartIncluding": "1.13.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@hashicorp.com"
}