CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.
History

Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric blmon
Vendors & Products Schneider-electric
Schneider-electric blmon

Wed, 10 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:30:00 +0000

Type Values Removed Values Added
Description CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published: 2025-09-09T21:12:35.969Z

Updated: 2025-09-10T19:34:21.734Z

Reserved: 2025-09-04T16:16:04.091Z

Link: CVE-2025-9997

cve-icon Vulnrichment

Updated: 2025-09-10T19:34:17.690Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T22:15:34.833

Modified: 2025-09-11T17:14:10.147

Link: CVE-2025-9997

cve-icon Redhat

No data.