Radiflow iSAP Smart Collector Restricted Shell Bypass Vulnerability

Vulnerability

A vulnerability in Radiflow iSAP Smart Collector running on CentOS 7 - VSAP 1.20 allows users with vpuser credentials to bypass the restrictions of a restricted shell (rbash) accessed via SSH. This flaw enables the user to gain access to a full-featured Linux shell, circumventing the limitations imposed by rbash.

Impact

Exploitation of this vulnerability allows for unauthorized escalation of privileges by gaining access to a full Linux shell, potentially leading to further exploitation of the system.

Added: Jul 9, 2025, 9:25 AM
Updated: Jul 9, 2025, 10:16 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.