HIGH
Authentication Hijack
Published Aug 20, 2025
8.5
HIGHCVSS 4.0
EPSS 0.11%
Description
The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.
Affected products
-
- Version 0StatusaffectedConstraints<=47.96.0
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Any customers using sdm-cli below version 47.97.0 should update to or beyond version 47.97.0.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner StrongDM
Published Aug 20, 2025
Updated Aug 20, 2025
Reserved Jun 16, 2025
Link CVE-2025-6180
CISA Vulnrichment
Updated Aug 20, 2025
ENISA EUVD
EUVD-2025-25352 Assigner StrongDM
Published Aug 20, 2025
Updated Aug 20, 2025
Exploited since n/a
Link EUVD-2025-25352