VulnAI


EUVD-2025-20792

ID: EUVD-2025-20792

Severity: medium

CVSS v4: Not provided

CVSS v3: 6.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N)

CWE: None listed

Source: ENISA

Description

The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash).

Timestamps

References

No references provided.