Vulnerability Description
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: they can call that route infinitely which will return the message that password is wrong until it is correct. This vulnerability is fixed in 4.11.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vantage6 | Vantage6 | < 4.11.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-43863?
CVE-2025-43863 is a vulnerability with a CVSS score of 9.8 (CRITICAL). vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated ...
How severe is CVE-2025-43863?
CVE-2025-43863 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-43863?
Check the references section above for vendor advisories and patch information. Affected products include: Vantage6 Vantage6.