« Volver al listado

CVE-2025-6037

Estado: AnalizadaMedia (6.8)—

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In this configuration, an attacker may be able to craft a malicious certificate that could be used to impersonate another user. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-6037",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-6037",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-02T03:55:53.917718Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@hashicorp.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@hashicorp.com",
      "affectedData": [
        {
          "repo": "https://github.com/hashicorp/vault",
          "vendor": "HashiCorp",
          "product": "Vault",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.20.1",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "64 bit",
            "32 bit",
            "x86",
            "ARM",
            "MacOS",
            "Windows",
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://github.com/hashicorp/vault",
          "vendor": "HashiCorp",
          "product": "Vault Enterprise",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "1.19.7",
                  "status": "unaffected"
                },
                {
                  "at": "1.18.12",
                  "status": "unaffected"
                },
                {
                  "at": "1.16.23",
                  "status": "unaffected"
                }
              ],
              "version": "0",
              "lessThan": "1.20.1",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "64 bit",
            "32 bit",
            "x86",
            "ARM",
            "MacOS",
            "Windows",
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-08-01T18:15:57.300",
  "references": [
    {
      "url": "https://discuss.hashicorp.com/t/hcsec-2025-18-vault-certificate-auth-method-did-not-validate-common-name-for-non-ca-certificates/76037",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@hashicorp.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@hashicorp.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In this configuration, an attacker may be able to craft a malicious certificate that could be used to impersonate another user. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23."
    },
    {
      "lang": "es",
      "value": "El método de autenticación de certificados TLS de Vault y Vault Enterprise («Vault») no validaba correctamente los certificados de cliente al configurarse con un certificado no perteneciente a una CA como [+certificado de confianza+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. En esta configuración, un atacante podría manipular un certificado malicioso que podría usarse para suplantar la identidad de otro usuario. Corregido en Vault Community Edition 1.20.1 y Vault Enterprise 1.20.1, 1.19.7, 1.18.12 y 1.16.23."
    }
  ],
  "lastModified": "2026-06-17T10:01:02.560",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FACD8B3A-DF81-45FE-A046-C52946E2FCC4",
              "versionEndExcluding": "1.16.23"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AC59271-E95C-433B-A789-F30C3DDBD579",
              "versionEndExcluding": "1.20.1"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E750D53-BBA7-4922-85CA-E55852B0A23A",
              "versionEndExcluding": "1.18.12",
              "versionStartIncluding": "1.17.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE2F3725-EADA-4406-9D63-8EDAF161CE2A",
              "versionEndExcluding": "1.19.7",
              "versionStartIncluding": "1.19.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:1.20.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "562AD4B9-82F5-45C4-9214-7428247B790A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@hashicorp.com"
}