Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18202 | vantage6 lacks brute-force protection on change password functionality |
Github GHSA |
GHSA-j6g5-p62x-58hw | vantage6 lacks brute-force protection on change password functionality |
Wed, 17 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vantage6:vantage6:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: they can call that route infinitely which will return the message that password is wrong until it is correct. This vulnerability is fixed in 4.11. | |
| Title | vantage6 lacks brute-force protection on change password functionality | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-12T17:54:44.017Z
Reserved: 2025-04-17T20:07:08.556Z
Link: CVE-2025-43863
Updated: 2025-06-12T17:54:34.712Z
Status : Analyzed
Published: 2025-06-12T18:15:20.533
Modified: 2025-09-17T18:46:49.757
Link: CVE-2025-43863
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:51:38Z
EUVD
Github GHSA