Junglewise Threat Intelligence

CVE-2020-8655: EyesOfNetwork Improper Privilege Management Vulnerability

CVE-2020-8655 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Executive brief

EyesOfNetwork 5.3 contains an improper privilege management vulnerability in its sudoers configuration. An attacker with apache user privileges can escalate to root by executing arbitrary commands via a crafted Nmap Scripting Engine (NSE) script using nmap7.

Affected products

  • EyesOfNetwork EyesOfNetwork 5.3

Timeline

  • 2020-02-06: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats