QID 378126

Date Published: 2023-03-28

QID 378126: PowerShell Universal Multiple Vulnerabilities

PowerShell Universal is a platform for providing non-technical users access to scripts and tools developed by your team.

Affected versions:
PowerShell Universal v2.0.0-v2.12.5
PowerShell Universal v3.0.0-v3.4.6
PowerShell Universal v3.5.0-v3.5.2
QID Detection Logic (Authenticated)
This QID checks for vulnerable versions of PowerShell Universal via Registry.

It allows an attacker with a valid app token to retrieve other app tokens.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    For more information regarding the update psu-2022-11-cve
    Vendor References

    CVEs related to QID 378126

    Software Advisories
    Advisory ID Software Component Link
    psu-2022-11-cve URL Logo blog.ironmansoftware.com/psu-2022-11-cve/