Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2025-9588

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563.

View on NVD

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-78

EPSS

Probability of exploitation (next 30 days): 0.0040 (0.4%)
Percentile: 61.1%
EPSS: 2026-06-05

Affects

ironmountain:envisionlinux:linux_kernel

Technical description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563.

Published: 9/23/2025, 8:15:39 AM
Last modified: 6/5/2026, 12:16:35 PM

References

HomeEventsBlogResourcesTeam