« Volver al listado

CVE-2025-6203

Estado: AnalizadaAlta (7.5)—

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unresponsive. This vulnerability, CVE-2025-6203, is fixed in Vault Community Edition 1.20.3 and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Aplicación expuesta en red (AV:N, PR:N, UI:N) explotable con payload malicioso. CWE-770 y descripción de consumo excesivo de CPU/memoria causando timeout → Ataque de disponibilidad (DoS).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-6203",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-6203",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-29T13:36:43.373189Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@hashicorp.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@hashicorp.com",
      "affectedData": [
        {
          "repo": "https://github.com/hashicorp/vault",
          "vendor": "HashiCorp",
          "product": "Vault",
          "versions": [
            {
              "status": "affected",
              "version": "1.15.0",
              "lessThan": "1.21.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "64 bit",
            "32 bit",
            "x86",
            "ARM",
            "MacOS",
            "Windows",
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://github.com/hashicorp/vault",
          "vendor": "HashiCorp",
          "product": "Vault Enterprise",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "1.20.5",
                  "status": "unaffected"
                },
                {
                  "at": "1.19.11",
                  "status": "unaffected"
                },
                {
                  "at": "1.16.27",
                  "status": "unaffected"
                }
              ],
              "version": "1.15.0",
              "lessThan": "1.21.2",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "64 bit",
            "32 bit",
            "x86",
            "ARM",
            "MacOS",
            "Windows",
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-08-28T20:15:43.817",
  "references": [
    {
      "url": "https://discuss.hashicorp.com/t/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads/76393",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@hashicorp.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@hashicorp.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unresponsive. This vulnerability, CVE-2025-6203, is fixed in Vault Community Edition 1.20.3 and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25."
    },
    {
      "lang": "es",
      "value": "Un usuario malintencionado puede enviar una carga útil compleja especialmente diseñada que, por lo demás, cumple con el límite de tamaño de solicitud predeterminado, lo que resulta en un consumo excesivo de memoria y CPU de Vault. Esto puede provocar un tiempo de espera en la subrutina de auditoría de Vault, lo que podría resultar en que el servidor de Vault deje de responder. Esta vulnerabilidad, CVE-2025-6203, está corregida en Vault Community Edition 1.20.3 y Vault Enterprise 1.20.3, 1.19.9, 1.18.14 y 1.16.25."
    }
  ],
  "lastModified": "2026-09-26T00:10:00.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C75B707B-CECA-4F3F-B7A5-3A63627E23E0",
              "versionEndExcluding": "1.16.27",
              "versionStartIncluding": "1.15.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFB5EFCB-595D-405C-AEE5-D3A674079A42",
              "versionEndExcluding": "1.21.0",
              "versionStartIncluding": "1.15.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB39834B-EF79-4C8B-B344-D81B15652821",
              "versionEndExcluding": "1.18.15",
              "versionStartIncluding": "1.18.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "167CFBBB-E0DF-42AB-84AA-4BF19C3873DB",
              "versionEndExcluding": "1.19.11",
              "versionStartIncluding": "1.19.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "466A7DC1-B9A3-4413-AA3E-AFAF34350E52",
              "versionEndExcluding": "1.20.5",
              "versionStartIncluding": "1.20.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@hashicorp.com"
}