VulnerabilityModified
CVE-2025-11344
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1.
MEDIUM 5.3EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from remote. Upgrading to version 8.24, 9.14 and 10.2 addresses this issue. It is recommended to upgrade the affected component.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-94
- Affected
- ilias/ilias
- Source
- cna@vuldb.com
References
- https://docu.ilias.de/go/blog/15821/882Release Notes, Vendor Advisory
- https://vuldb.com/?ctiid.327229Permissions Required, VDB Entry
- https://vuldb.com/?id.327229Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.664889Third Party Advisory, VDB Entry
- https://srlabs.de/blog/breaking-ilias-part-2-three-to-rce
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.