VYPR

StrongDM

by StrongDM

CVEs (4)

  • CVE-2025-6182HigAug 20, 2025
    risk 0.55cvss epss 0.00

    The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.

  • CVE-2025-6181HigAug 20, 2025
    risk 0.55cvss epss 0.00

    The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

  • CVE-2025-6180HigAug 20, 2025
    risk 0.55cvss epss 0.00

    The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.

  • CVE-2026-4387LowMay 29, 2026
    risk 0.13cvss epss 0.00

    StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\\.sdm\state.kv. The file is…