S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-8654 Scanner

CVE-2020-8654 scanner - OS Command Injection vulnerability in EyesOfNetwork

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-8654
8.8
CVSS

An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

EyesOfNetwork is a network monitoring software used for network management and security monitoring purposes. It is designed to analyze the network and provide real-time monitoring and alerting for any suspicious activity. The software is used by IT professionals and network administrators to ensure the reliability and security of the network infrastructure.

CVE-2020-8654 is a recently discovered vulnerability in EyesOfNetwork 5.3. This vulnerability enables an authenticated web user with sufficient privileges to exploit the AutoDiscovery module. An attacker can abuse the autodiscovery.php target field to run arbitrary OS commands. This can be done by sending a specially crafted request to the software.

When this vulnerability is exploited, the attacker gains unauthorized access to the network. This can lead to a variety of consequences such as unauthorized data access, data breaches, network disruption, and business downtime. The attacker can also use this exploit to execute malicious code and install backdoors, providing them with unauthorized remote access to the network.

It is important for users to take proactive measures to protect their digital assets from potential cyber threats. With the advanced features of the s4e.io platform, readers can easily and quickly check for vulnerabilities in their digital assets. This platform provides quick and easy access to vulnerability assessments, security news, and threat intelligence. It is an essential tool for IT professionals and network administrators to ensure the reliability and security of their network infrastructure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update to the latest version of EyesOfNetwork software.
  • Limit access to the autodiscovery.php target field.
  • Monitor server logs and traffic for suspicious activity.
  • Implement network segmentation and access control.
  • Regularly check the security of the network infrastructure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-8654 scanner - OS Command Injection vulnerability in EyesOfNetwork S4E