CVE-2025-6180

Severity CVSS v4.0:
HIGH
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
20/08/2025
Last modified:
22/08/2025

Description

The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.