Radiflow iSAP Smart Collector Privilege Escalation Vulnerability Allowing Unauthorized File System Access
Vulnerability
A vulnerability exists in Radiflow iSAP Smart Collector running on CentOS 7 with VSAP 1.20, allowing the deprivileged user 'vpuser' to access the entire file system. This access includes files belonging to other users with restricted permissions, such as the root password hash. The issue arises from incorrect privilege assignment, enabling unauthorized file read operations across the system.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive files, including those with restricted permissions, potentially allowing for further privilege escalation or access to confidential information.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
