CVE-2025-43863 - CVE House
Back to Database
Status published Low CVE-2025-43863

vantage6 lacks brute-force protection on change password functionality

Vulnerability Description

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: they can call that route infinitely which will return the message that password is wrong until it is correct. This vulnerability is fixed in 4.11.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-43863

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

vantage6
Vulnerable Versions:
< 4.11.0

Timeline

Official Publish: June 12th, 2025
Last Modified: June 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)