← back
CVE-2025-6182

Root Certificate Injection

CVSS 8.5 HIGHEPSS 0.1%CWE-269
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.5EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
20 Aug 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
StrongDM · sdm

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →