CVSS 10.0CVSS 10.0 · CRITICAL
CVE-2025-9588ironmountain envision vulnerability
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563.
View on NVDSeverity
Score: 10.0(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-78EPSS
Probability of exploitation (next 30 days): 0.0040 (0.4%)
Percentile: 61.1%
EPSS: 2026-06-05
Affects
ironmountain:envisionlinux:linux_kernelTechnical description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563.
Published: 9/23/2025, 8:15:39 AM
Last modified: 6/5/2026, 12:16:35 PM