Логотип exploitDog
bind:CVE-2025-27027
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-27027

Количество 2

Количество 2

nvd логотип

CVE-2025-27027

7 месяцев назад

A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-wwjg-89vg-gfhh

7 месяцев назад

Restricted shell rbash evasion in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) allows the user vpuser to start a full-feature shell. A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.

CVSS3: 4.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-27027

A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.

CVSS3: 4.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-wwjg-89vg-gfhh

Restricted shell rbash evasion in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) allows the user vpuser to start a full-feature shell. A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.

CVSS3: 4.1
0%
Низкий
7 месяцев назад

Уязвимостей на страницу