CVE-2023-4680
Estado: ModificadaMedia (6.8)—
HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.44%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-323
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-4680",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-4680",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-25T19:52:32.242060Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@hashicorp.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "security@hashicorp.com",
"affectedData": [
{
"repo": "https://github.com/hashicorp/vault",
"vendor": "HashiCorp",
"product": "Vault",
"versions": [
{
"status": "affected",
"version": "1.14.0",
"lessThan": "1.14.3",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.13.0",
"lessThan": "1.13.7",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.12.0",
"lessThan": "1.12.11",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.6.0",
"lessThan": "1.12.0",
"versionType": "semver"
}
],
"platforms": [
"64 bit",
"32 bit",
"x86",
"ARM",
"MacOS",
"Windows",
"Linux"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://github.com/hashicorp/vault",
"vendor": "HashiCorp",
"product": "Vault Enterprise",
"versions": [
{
"status": "affected",
"version": "1.14.0",
"lessThan": "1.14.3",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.13.0",
"lessThan": "1.13.7",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.12.0",
"lessThan": "1.12.11",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.6.0",
"lessThan": "1.12.0",
"versionType": "semver"
}
],
"platforms": [
"64 bit",
"32 bit",
"x86",
"ARM",
"MacOS",
"Windows",
"Linux"
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*"
],
"vendor": "hashicorp",
"product": "vault",
"versions": [
{
"status": "affected",
"version": "1.14.0",
"lessThan": "1.14.3",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.13.0",
"lessThan": "1.13.7",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.12.0",
"lessThan": "1.12.11",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.6.0",
"lessThan": "1.12.0",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:hashicorp:vault_enterprise:*:*:*:*:*:*:*:*"
],
"vendor": "hashicorp",
"product": "vault_enterprise",
"versions": [
{
"status": "affected",
"version": "1.14.0",
"lessThan": "1.14.3",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.13.0",
"lessThan": "1.13.7",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.12.0",
"lessThan": "1.12.11",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.6.0",
"lessThan": "1.12.0",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2023-09-15T00:15:07.967",
"references": [
{
"url": "https://discuss.hashicorp.com/t/hcsec-2023-28-vault-s-transit-secrets-engine-allowed-nonce-specified-without-convergent-encryption/58249",
"tags": [
"Vendor Advisory"
],
"source": "security@hashicorp.com"
},
{
"url": "https://discuss.hashicorp.com/t/hcsec-2023-28-vault-s-transit-secrets-engine-allowed-nonce-specified-without-convergent-encryption/58249",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@hashicorp.com",
"description": [
{
"lang": "en",
"value": "CWE-323"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11."
},
{
"lang": "es",
"value": "El motor de secretos de tránsito de HashiCorp Vault y Vault Enterprise permitió a los usuarios autorizados especificar nonces arbitrarios, incluso con el cifrado convergente deshabilitado. El endpoint de cifrado, en combinación con un ataque fuera de línea, podría usarse para descifrar texto cifrado arbitrario y potencialmente derivar la subclave de autenticación cuando se utiliza el motor de secretos de tránsito sin cifrado convergente. Introducido en 1.6.0 y corregido en 1.14.3, 1.13.7 y 1.12.11."
}
],
"lastModified": "2026-06-17T06:38:21.450",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88214AA6-BE16-44D0-8BF3-961AA4F4912C",
"versionEndExcluding": "1.12.11",
"versionStartIncluding": "1.6.0"
},
{
"criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "308AEF45-E549-4EA3-8028-3A95978BF44C",
"versionEndExcluding": "1.12.11",
"versionStartIncluding": "1.6.0"
},
{
"criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1190B84C-4AE0-4353-A7B3-64B646E4BCA5",
"versionEndExcluding": "1.13.7",
"versionStartIncluding": "1.13.0"
},
{
"criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "148E1E7C-5DB9-4261-BF3B-A54C8B5F43EA",
"versionEndExcluding": "1.13.7",
"versionStartIncluding": "1.13.0"
},
{
"criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "931AAAF6-4AB0-46EB-A03F-FF98A22867C2",
"versionEndExcluding": "1.14.3",
"versionStartIncluding": "1.14.0"
},
{
"criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "778CBB0C-2739-4733-871A-9B053843FADC",
"versionEndExcluding": "1.14.3",
"versionStartIncluding": "1.14.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@hashicorp.com"
}