ZeroHour

CVE-2020-8655

KEV PoC ×3niche

Privilege Escalation to Root in EyesOfNetwork 5.3 via Sudo Nmap NSE Scripts

CISA: EyesOfNetwork Improper Privilege Management Vulnerability

CVSS 3.1
7.8 high
EPSS
60%p99
Published
()
KEV added
AI analysis

EyesOfNetwork 5.3 ships a sudoers configuration that grants the apache user the ability to run nmap 7 as root without a password, an improper privilege management flaw (CWE-269). A local attacker who has already obtained code execution in the apache user's context, typically through the monitoring platform's web application, can supply a crafted NSE (Lua) script that nmap executes with root privileges. Successful exploitation yields arbitrary command execution as root, giving the attacker full control of the monitoring server with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Organizations running EyesOfNetwork 5.3 are affected. The flaw has public proof-of-concept exploits, a 60.1% EPSS score (99th percentile), and was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03, indicating exploitation in the wild.

What to do: Apply EyesOfNetwork updates per the vendor's instructions, prioritizing internet-facing monitoring servers since the issue is on CISA KEV with a high EPSS score. As an interim mitigation, audit /etc/sudoers for the apache user's passwordless nmap entry and restrict it so nmap cannot run attacker-controlled NSE scripts (e.g., limit scripts to a trusted, non-writable directory) or remove the sudo grant. Review apache and nmap process logs for signs of prior root-level compromise.

Affected
EyesOfNetwork5.3
Estimated exposure
nichelikely low thousands of deployments worldwide (no published install or internet-exposure counts in the data) — EyesOfNetwork is a niche open-source network monitoring distribution with no install-count or scan data available, so this order-of-magnitude estimate rests on its limited, monitoring-focused deployment pattern.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to run arbitrary commands as root via a crafted NSE script for nmap 7.

CISA Known Exploited Vulnerability
Affected
EyesOfNetwork EyesOfNetwork
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
eyesofnetwork
Products
eyesofnetwork
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.