VYPR

iSAP Smart Collector

by Radiflow

CVEs (3)

  • CVE-2025-3498CriJul 9, 2025
    risk 0.64cvss 9.9epss 0.00

    An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). An…

  • CVE-2025-3497HigJul 9, 2025
    risk 0.57cvss 8.7epss 0.00

    The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vulnerability could be exploited to affect this product.

  • CVE-2025-27028MedJul 9, 2025
    risk 0.44cvss 6.8epss 0.00

    The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash).