CRITICAL

CVE-2021-27514

CVSS v3

9.8

CRITICAL

EPSS Score

13.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).

Technical details

Published
2/22/2021

Frequently asked questions

What is CVE-2021-27514?

EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).

Is CVE-2021-27514 actively exploited?

Active exploitation of CVE-2021-27514 has not been confirmed. The EPSS score is 13.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-27514?

CVE-2021-27514 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-27514 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.