Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and write arbitrary files.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.