PT-2025-1364 · Nmap+1 · Nmap+1

Guilhem Rioux

·

Published

2025-01-07

·

Updated

2025-06-13

·

CVE-2022-41572

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EyesOfNetwork (EON) versions 5.3.11 and earlier
Description An issue in EyesOfNetwork allows privilege escalation on the server because nmap can be run as root, giving the attacker total control over the server.
Recommendations For EyesOfNetwork (EON) versions 5.3.11 and earlier, consider restricting the execution of nmap to prevent privilege escalation until a patch is available. As a temporary workaround, limit the privileges of the user running nmap to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-41572

Affected Products

Eyesofnetwork
Nmap