PT-2025-37997 · Unknown · Pspas Powershell Module

·

CVE-2025-59270

·

Published

2025-09-16

·

Updated

2025-09-26

CVSS v3.1

3.1

Low

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions psPAS PowerShell module versions prior to 7.0.209
Description The psPAS PowerShell module does not enforce TLS 1.2 within the Get-PASSAMLResponse function during the SAML authentication process. This allows an unauthenticated attacker in a 'Man-in-the-Middle' position to potentially downgrade the TLS protocol to a deprecated version by manipulating the TLS handshake.
Recommendations Update to version 7.0.209 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59270

Affected Products

Pspas Powershell Module