Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2025-9588

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563.

Ver en NVD

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-78

EPSS

Probabilidad de explotación (próx. 30 días): 0.0040 (0.4%)
Percentil: 61.1%
EPSS: 2026-06-05

Afecta

ironmountain:envisionlinux:linux_kernel

Descripción técnica

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563.

Publicada: 23/9/2025, 8:15:39
Última modificación: 5/6/2026, 12:16:35

Referencias

InicioEventosBlogRecursosEquipo