CVSS 10.0CVSS 10.0 · CRITICAL
CVE-2025-9588ironmountain envision vulnerability
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563.
Ver en NVDSeveridad
Puntaje: 10.0(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE):
CWE-78EPSS
Probabilidad de explotación (próx. 30 días): 0.0040 (0.4%)
Percentil: 61.1%
EPSS: 2026-06-05
Afecta
ironmountain:envisionlinux:linux_kernelDescripción técnica
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563.
Publicada: 23/9/2025, 8:15:39
Última modificación: 5/6/2026, 12:16:35