CVE-2025-27028

The Linux deprivileged user vpuserĀ in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash).
Configurations

No configuration.

History

10 Jul 2025, 13:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 09:15

Updated : 2025-07-10 13:17


NVD link : CVE-2025-27028

Mitre link : CVE-2025-27028

CVE.ORG link : CVE-2025-27028


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment