EXPOSURES › CVE-2020-8655
CVE-2020-8655
HIGH ⌖ ON CISA KEV · EXPLOITEDEyesOfNetwork's improper privilege management flaw allowed Nmap scripts to execute root commands, enabling remote code execution.
An improper privilege management vulnerability in EyesOfNetwork allowed attackers to run arbitrary commands as root via crafted Nmap Scripting Engine scripts. This is a critical failure for DIB organizations because it enables remote code execution, bypassing standard network defenses and directly violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure all network scanning and monitoring tools are patched and validated against known KEV vulnerabilities.
Shame score — A privilege management flaw allowing root command execution via a widely used tool like Nmap is highly avoidable and represents a severe breach of basic security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.