CVE-2025-6180
Severity CVSS v4.0:
HIGH
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
20/08/2025
Last modified:
22/08/2025
Description
The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH



