CVE-2020-29576

The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
eggheadseggdrop_docker_image
1.6
eggheadseggdrop_docker_image
1.6.21
eggheadseggdrop_docker_image
1.8.0
eggheadseggdrop_docker_image
1.8.0:rc1
eggheadseggdrop_docker_image
1.8.0:rc2
eggheadseggdrop_docker_image
1.8.0:rc3
eggheadseggdrop_docker_image
1.8.0:rc4
eggheadseggdrop_docker_image
1.8.1
eggheadseggdrop_docker_image
1.8.1:rc2
eggheadseggdrop_docker_image
1.8.2
eggheadseggdrop_docker_image
1.8.2:rc1
eggheadseggdrop_docker_image
1.8.2:rc2
eggheadseggdrop_docker_image
1.8.3
eggheadseggdrop_docker_image
1.8.3:rc1
eggheadseggdrop_docker_image
1.8.4
eggheadseggdrop_docker_image
1.8.4:rc1
eggheadseggdrop_docker_image
1.8.4:rc2
eggheadseggdrop_docker_image
1.8.4:rc3
𝑥
= Vulnerable software versions