
Cloud Vulnerability DB
A community-led vulnerabilities database
EyesOfNetwork 5.3-10 contains a session ID vulnerability (CVE-2021-27514) where the application uses an integer between 8 and 10 digits for the session ID, which could be leveraged for brute-force authentication bypass. This vulnerability was discovered and disclosed in February 2021 (CISA Bulletin).
The vulnerability exists in the session ID implementation where the application generates session IDs using only 8-10 digits, making them predictable and susceptible to brute-force attacks. This weakness in the session ID generation could be exploited in conjunction with other vulnerabilities like CVE-2021-27513 for authentication bypass (MITRE CVE).
If successfully exploited, this vulnerability could allow an attacker to bypass authentication mechanisms through brute-force attacks on the session ID. This could potentially lead to unauthorized access to the application with administrative privileges (CISA Bulletin).
The vulnerability is exploitable by remote attackers who can attempt to brute-force the session ID due to its predictable format. Proof-of-concept code has been published demonstrating the exploitation of this vulnerability in combination with CVE-2021-27513 (GitHub PoC).
The vulnerability was addressed in versions after 5.3-10 by implementing MD5 hashing for session IDs. However, it has been noted that this mitigation might not be completely effective as the hashed values could still be pre-computed for brute-force attempts (GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."