CVE-2025-11673
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-13
Last updated on: 2025-10-14
Assigner: TWCERT/CC
Description
Description
SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| piextract | soop-clm | 4.0 |
| piextract | soop-clm | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-912 | The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in SOOP-CLM developed by PiExtract is a Hidden Functionality vulnerability that allows privileged remote attackers to exploit a hidden feature in the software to execute arbitrary code on the server.
How can this vulnerability impact me? :
The vulnerability can allow attackers with privileged remote access to execute arbitrary code on the server, potentially leading to full compromise of the affected system, including data theft, service disruption, or further attacks within the network.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70