CVE-2025-27027

A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.
Configurations

No configuration.

History

10 Jul 2025, 13:17

Type Values Removed Values Added
Summary
  • (es) Un usuario con credenciales de usuario virtual que abre una conexión SSH al dispositivo obtiene un shell rbash restringido que solo permite una pequeña lista de comandos permitidos. Esta vulnerabilidad permite al usuario obtener un shell Linux completo, eludiendo las restricciones de rbash.

09 Jul 2025, 10:15

Type Values Removed Values Added
Summary (en) Restricted shell rbash evasion in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) allows the user vpuser to start a full-feature shell. A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions. (en) A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.
CWE CWE-653

09 Jul 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 09:15

Updated : 2025-07-10 13:17


NVD link : CVE-2025-27027

Mitre link : CVE-2025-27027

CVE.ORG link : CVE-2025-27027


JSON object : View

Products Affected

No product.

CWE
CWE-653

Improper Isolation or Compartmentalization