Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25349 | The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones. |
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Strongdm Strongdm sdm-cli |
|
| Vendors & Products |
Microsoft
Microsoft windows Strongdm Strongdm sdm-cli |
Wed, 20 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones. | |
| Title | Root Certificate Injection | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: StrongDM
Published:
Updated: 2025-08-20T17:39:08.716Z
Reserved: 2025-06-16T16:57:25.868Z
Link: CVE-2025-6182
Updated: 2025-08-20T17:39:01.588Z
Status : Deferred
Published: 2025-08-20T17:15:37.453
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-6182
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:30:53Z
EUVD