216.73.216.197

CVE-2025-59270

· Published 16/09/2025 15:15 · Modified 17/09/2025 14:18

Labels: CVE-2025-59270 2025-09-169119a7d8-5eab-497f-8521-727c672e3725CVE-2025-59270CWE-757

Essential information

Published
16/09/2025 15:15
Modified
17/09/2025 14:18
Author
Creator
CVSS
2.3 LOW (v3) 2.3 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML authentication process. An unauthenticated attacker in a 'Man-in-the-Middle' position could manipulate the TLS handshake and downgrade TLS to a deprecated protocol. Fixed in 7.0.209.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / pspas cpe:2.3:a:*:pspas:7.0.209:*:*:*:*:*:*:*

References