Skip to content
COOEY

EXPOSURES › CVE-2020-8657

CVE-2020-8657

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8657 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wilddefault-credshardcoded-creds

EyesOfNetwork shipped with hard-coded API keys allowing attackers to guess admin access tokens.

The vendor used the same API key by default, enabling attackers to calculate or guess admin access tokens. DIB organizations must ensure no default or hard-coded credentials exist in their supply chain, as this directly violates CMMC/NIST 800-171 requirements for access control and system integrity. Immediate action requires replacing default credentials and implementing strict credential rotation policies.

Shame score — Hard-coded credentials are a fundamental, avoidable security failure that directly enables unauthorized access and violates core compliance requirements.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.70
cooey ↗ negative -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.