CVE-2020-29577

The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
zncznc_docker_image
1.6
zncznc_docker_image
1.6-slim
zncznc_docker_image
1.6.4
zncznc_docker_image
1.6.4-slim
zncznc_docker_image
1.6.5
zncznc_docker_image
1.6.5-slim
zncznc_docker_image
1.6.6
zncznc_docker_image
1.6.6-slim
zncznc_docker_image
1.7.0
zncznc_docker_image
1.7.0-slim
zncznc_docker_image
1.7.1-slim
𝑥
= Vulnerable software versions