Skip to content
COOEY

EXPOSURES › CVE-2020-8655

CVE-2020-8655

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8655 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildrceunpatched

EyesOfNetwork's improper privilege management flaw allowed Nmap scripts to execute root commands, enabling remote code execution.

An improper privilege management vulnerability in EyesOfNetwork allowed attackers to run arbitrary commands as root via crafted Nmap Scripting Engine scripts. This is a critical failure for DIB organizations because it enables remote code execution, bypassing standard network defenses and directly violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure all network scanning and monitoring tools are patched and validated against known KEV vulnerabilities.

Shame score — A privilege management flaw allowing root command execution via a widely used tool like Nmap is highly avoidable and represents a severe breach of basic security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.