StrongDM
First CVE: Aug 20, 2025Active for: 1 year
5
CVEs Published
More CVEs Published than 15% of tracked CNAs
2.5
Avg CVEs / Year
More Avg CVEs / Year than 16% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by StrongDM over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2025
11 months ago
Most Recent CVE
May 29, 2026
56 days ago
Top CVEs
All CVEs published by StrongDM as a CNA, regardless of affected vendor or product.
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6182HIGH The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificate | Aug 20, 2025 | 8.5 | 27 | NO | NO |
CVE-2025-6181HIGH The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation. | Aug 20, 2025 | 8.5 | 27 | NO | NO |
CVE-2025-6180HIGH The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication c | Aug 20, 2025 | 8.5 | 27 | NO | NO |
CVE-2025-6183HIGH The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a malicious JSON message. | Aug 20, 2025 | 7.0 | 23 | NO | NO |
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material | May 29, 2026 | 2.0 | 22 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA5 CVEs
20%
80%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowHigh
Attack Vector
Local5 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (60.0%)
High0 (0.0%)
None2 (40.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by StrongDM as a CNA.
Media Mentions
Media articles that mention a CVE ID published by StrongDM as a CNA — matched by CVE ID, not by organization name.