CVE-2020-8657

CVE Published 2020-02-06
Related CWE(s) CWE-798: Use of Hard-coded Credentials
Related Vendor(s) eyesofnetwork
Related Product(s) eyesofnetwork
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References