10
CVE-2025-9588
- EPSS 1.13%
- Veröffentlicht 23.09.2025 08:15:39
- Zuletzt bearbeitet 05.06.2026 12:16:35
- Quelle iletisim@usom.gov.tr
- CVE-Watchlists
- Unerledigt
OS Command Injection in Iron Mountain's enVision
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection.
This issue affects enVision: before 250563.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ironmountain ≫ Envision Version < 250563
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.13% | 0.62 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| iletisim@usom.gov.tr | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://www.usom.gov.tr/bildirim/tr-25-0285
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0285