QID 730386
Date Published: 2022-03-09
QID 730386: EyesOfNetwork Multiple Vulnerabilities
EyesOfNetwork is a global supervision solution for the hardware status of equipment, operating systems, standard applications, business applications and performance.
Affected Versions:
EyesOfNetwork 5.2 and 5.3
QID Detection Logic(Unauthenticated):
This QID sends a crafted SQLI payload to /eonapi/getApiKey endpoint and tries to extract the admin API key
Successful exploitation of the vulnerability may allow remote code execution and complete system compromise.
Solution
Vendor has released patch, for more information please refer to EyesOfNetwork Security Advisory
Vendor References
- EyesOfNetwork Security Advisory -
www.eyesofnetwork.com/en/news/vulnerability
CVEs related to QID 730386
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EyesOfNetwork Security Advisory |
|