Third Party Index

Snapshot 35170

Document
Trust center
URL
https://security.strongdm.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
410522 bytes
SHA-256 (raw)
b937f16d40f8847d84e3a687d974f5922ec2a900245b98f3e5288363f180182e
SHA-256 (normalized text)
44952b87e960e841874cb83af8e31f54d08fad4dc5318a54b4ec595eb8371ef7

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Start your security review
View & download sensitive information
Ask for information
Overview
StrongDM's Security & Compliance Programs are rooted in providing our Customers with the most secure infrastructure access platform on the market. If you have further questions beyond the information provided here, please reach out to your sales representative, or your Customer Success Manager at [email protected]. If you're interested in the StrongDM Platform, and how it can solve your Infrastructure Access problems, please reach out to [email protected]
Compliance
PCI DSS v4.0.0
SOC 2 Type 2
CCPA
GDPR
VPAT
StrongDM is reviewed and trusted by
Benevity
Better
Bloom Credit
Braze
Coveo
Seismic
Sequoia Capital
SoFi
StackAdapt
Yext
Zefr
Documents
Featured Documents
REPORTSSOC 2 Report
COMPLIANCEPCI DSS v4.0.0
Risk Profile
Data Access LevelRestricted
Impact LevelSubstantial
Recovery Time Objective12 hours
View more
Policies
Access Control Policy
Contingency Planning Policy
Data Classification Policy
View more
Reports
Data Flow Diagram (DFD)
Network Diagram
Other Reports
View more
Self-Assessments
CAIQ Lite
SIG Lite
VSA Core
Product Security
Audit Logging
Data Security
Integrations
View more
Data Security
Access Monitoring
Data Backups
Encryption-at-rest
View more
App Security
Responsible Disclosure
Application Penetration Testing
Code Analysis
View more
Legal
Subprocessors
Customer Audit Rights
Data Processing Agreement
View more
Data Privacy
Cookies
Data Breach Notifications
Data Privacy Officer
View more
Access Control
Data Access
Logging
Password Security
Infrastructure
Status Monitoring
Amazon Web Services
Anti-DDoS
View more
Endpoint Security
Disk Encryption
Endpoint Detection & Response
Mobile Device Management
Network Security
Firewall
IDS/IPS
Security Information and Event Management
View more
Corporate Security
Email Protection
Employee Training
HR Security
View more
Security Grades
SecurityScorecard
strongdm.com
Qualys SSL Labs
StrongDM Platform AdminUI
A+
StrongDM Platform API
A+
Security Headers
StrongDM Platform AdminUI
A
Trust Center Updates
Security Advisories (StrongDM Products)
Vulnerabilities
SDMSA-2026-001 (CVE-2026-4387)
Summary
Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file.
Affected Products & Versions
StrongDM Desktop Application (Windows): all versions below 23.74.0
StrongDM Desktop Client (Windows): all versions below 53.77.0
Solution
Update to StrongDM Desktop Application 23.74.0 or Desktop Client 53.77.0 or later.
Vulnerability Details
CVE ID: CVE-2026-4387
CVSS v4.0 Score: 2.0
CWE Class: CWE-312 Cleartext Storage
Acknowledgments
StrongDM thanks Hope Walker (SpecterOps) for responsibly reporting this vulnerability.
SDMSA-2025-004 (CVE-2025-6183)
Summary
The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a malicious JSON message.
Affected Products & Versions
The configuration injection vulnerability affects all MacOS client application CLI versions below sdm-cli 47.39.0.
Solution
Any customers using MacOS sdm-cli below version 47.39.0 should update to or beyond version 47.39.0
Vulnerability Details
CVE ID: CVE-2025-6183
CVSS v4.0 Score: 7.0
CVE Description: configd Injection
CWE Class: CWE-78: OS Command Injection
Acknowledgments
StrongDM would like to thank WithSecure/Reversec for responsibly reporting this vulnerability.
SDMSA-2025-003 (CVE-2025-6182)
Summary
The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.
Affected Products & Versions
The command injection vulnerability affects all Windows client application CLI versions below sdm-cli 47.50.0.
Solution
Any customers using Windows sdm-cli below version 47.50.0 should update to or beyond version 47.50.0
Vulnerability Details
CVE ID: CVE-2025-6182
CVSS v4.0 Score: 8.5
CVE Description: Root Certificate Injection
CWE Class: CWE-269: Improper Privilege Management
Acknowledgments
StrongDM would like to thank WithSecure/Reversec for responsibly reporting this vulnerability.
SDMSA-2025:002 (CVE-2025-6181)
Summary
The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.
Affected Products & Versions
The command injection vulnerability affects all Windows client application CLI versions below sdm-cli 47.39.0.
Solution
Any customers using Windows sdm-cli below version 47.39.0 should update to or beyond version 47.39.0
Vulnerability Details
CVE ID: CVE-2025-6181
CVSS v4.0 Score: 8.5
CVE Description: PowerShell Command Injection
CWE Class: CWE-78: OS Command Injection
Acknowledgments
StrongDM would like to thank WithSecure/Reversec for responsibly reporting this vulnerability.
SDMSA-2025:001 (CVE-2025-6180)
Summary
The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.
Affected Products & Versions
Authentication Hijack vulnerability affects all client application CLI version below sdm-cli 47.97.0.
Solution
Any customers using sdm-cli below version 47.97.0 should update to or beyond version 47.97.0
Vulnerability Details
CVE ID: CVE-2025-6180
CVSS v4.0 Score: 8.5
CVE Description: Authentication Hijack
CWE Class: CWE-319: Cleartext Transmission of Sensitive Information
Acknowledgments
StrongDM would like to thank WithSecure/Reversec for responsibly reporting this vulnerability.
Newsworthy Vulnerability Updates
Vulnerabilities
Statement on StrongDM's exposure to the React Server Components vulnerability (React2Shell)
We are aware of the critical security vulnerability (CVE-2025-55182), also known as React2Shell, disclosed by the React team on December 3, 2025, affecting React Server Components. This vulnerability, rated CVSS 10.0, allows unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints.
StrongDM does not use React Server Components in any production systems. Our internal review of the vulnerability, including analysis of our production dependencies and infrastructure, confirms that no StrongDM production systems are affected by this vulnerability.
We will continue to monitor the situation as the React team and affected framework maintainers release additional guidance, and will post updates to this notice as relevant information surfaces.
Originally published on March 27, 2025
Statement on StrongDM's exposure to Oracle Cloud's Breach
On March 21st, 2025, CloudSek Security released a report on a potential security incident involving Oracle Cloud. This report was updated on March 25th, 2025, to state approximately 140,000 tenants were affected by the security incident. The tool released by CloudSek indicated StrongDM was one of the Oracle tenants impacted.
StrongDM’s Oracle Cloud environment is strictly for research and technical demonstrations. We do not host any Customer Data in Oracle Cloud, nor do we host any production systems there. Because of the strict segmentation that StrongDM employs across our IaaS providers, the risk disclosure of Customer Data impact is very low.
Despite this very low assessed risk, StrongDM’s Security & Technology Teams launched an impact investigation and took a number of preemptive actions within StrongDM’s Oracle environment, including credential rotations and tightening account recovery and lockout settings. We comprehensively audited all logins and user activity and found no suspicious activity. StrongDM strictly enforces MFA for all logins and continuously monitors all administrator activities for indicators of compromise.
StrongDM will continue to monitor the situation and apply remediation measures as they develop.
Originally published on July 3, 2024
Update on RegreSSHion Vulnerability (CVE-2024-6387)
Qualys has identified a vulnerability in the OpenSSH utility, versions earlier than 4.4p1, and versions 8.5p1 up to, but not including, 9.8p1 are vulnerable to Remote Code Execution. The CVE is listed below with links to resources:
CVE-2024-6387
• NIST NVD
• MITRE CVE List
StrongDM's Trust team has investigated our environment for systems that could be affected by this vulnerability, and we have not found any systems that are publicly available with software affected by this vulnerability.
Originally published on June 22, 2023
StrongDM Not Impacted by the MOVEit Vulnerability
We recently became aware of a vulnerability within the file transfer software product, MOVEit. Reputable threat intelligence sources have reported that this incident impacts customers of this solution: https://www.securityweek.com/moveit-customers-urged-to-patch-third-critical-vulnerability/.
We want our customers and potential customers to know that StrongDM is not impacted by this vulnerability.
We do not use MOVEit within our product or business functions, in any capacity. We are also not aware of any usage of MOVEit software amongst our contracted third parties currently.
The OpenSSL Project has announced the availability of a security update (version 3.07) that addresses a vulnerability affecting OpenSSL versions 3.0 and above (3.0.0 - 3.0.6).
The two CVE's are listed below:
CVE-2022-3602
NIST NVD
MITRE CVE List
CVE-2022-3786
NIST NVD
MITRE CVE List
Response
StrongDM's Trust teams have enumerated the services that could be affected by these vulnerabilities, and no vulnerable versions of the OpenSSL software were found.
Trust Center Updates
Compliance
2022 Penetration Test Report Now Available
We are happy to announce the successful completion of a comprehensive penetration test of StrongDM's Platform AdminUI and API (also known as the "Control Plane").
In 2022, StrongDM engaged Cobalt Labs to conduct a gray-box penetration test and we are proud to present the results of this test in the 2022 Control Plane Penetration Test Combined Report.
If you think you may have discovered a vulnerability, please send us a note.
Report issue