LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8655: EyesOfNetwork Improper Privilege Management Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8655 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

CVE-2020-8655 is an improper privilege management flaw in EyesOfNetwork that can let a user escalate to root by supplying a crafted Nmap Scripting Engine (NSE) script to nmap7. For teams running this network monitoring platform, the issue matters because successful abuse yields full system control on the host where EyesOfNetwork is installed, with potential impact on monitoring data, credentials, and connected infrastructure.

Public detail is limited to the CISA description and the CWE-269 classification; exact affected versions, attack preconditions, and patch identifiers must be confirmed against the vendor advisory before you act.

How it works

The weakness is CWE-269 (Improper Privilege Management). In this class of flaw, the application fails to enforce correct privilege boundaries when it invokes or processes an external tool. According to the CISA summary, EyesOfNetwork allows a user to run commands as root by feeding a crafted NSE script to nmap7. An attacker who already has some level of access sufficient to supply or influence that script can therefore obtain root-level execution on the EyesOfNetwork host. No further exploit mechanics are provided in the public record; defenders should treat any untrusted or user-controlled NSE input path as the attack surface and verify the precise conditions in the vendor advisory.

Am I affected? How to find it in your systems

EyesOfNetwork is typically deployed as a network and infrastructure monitoring appliance or server, often on Linux hosts inside operations or NOC environments. Inventory steps:

If you cannot determine the exact build, assume the instance is vulnerable until the vendor advisory confirms otherwise.

How to remediate

Patch first. Apply the updates supplied by the EyesOfNetwork vendor exactly as directed in their advisory (CISA’s required action is “Apply updates per vendor instructions”). After patching:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures only buy time; they do not replace the vendor patch.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities frequently precede broader compromise and data theft. If you have evidence of exploitation or cannot rule it out, treat the EyesOfNetwork host and any credentials or monitoring data it held as potentially exposed: isolate the system, preserve logs, rotate secrets, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedEyesOfNetwork · EyesOfNetwork
WeaknessCWE-269
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities