Vulnerability Name:

CVE-2020-29576 (CCN-192864)

Assigned:2020-12-07
Published:2020-12-07
Updated:2020-12-22
Summary:The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2020-29576

Source: XF
Type: UNKNOWN
eggdrop-cve202029576-sec-bypass(192864)

Source: CCN
Type: koharin2 GIT Repository
CVE-2020-29576

Source: MISC
Type: Third Party Advisory
https://github.com/koharin/koharin2/blob/main/CVE-2020-29576

Source: CCN
Type: Docker Web site
eggdrop Docker image

Vulnerable Configuration:Configuration 1:
  • cpe:/a:eggheads:eggdrop_docker_image:1.6:*:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.6.21:*:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.0:rc3:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.0:rc4:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.1:rc2:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.2:rc1:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.2:rc2:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.3:*:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.3:rc1:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.4:*:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.4:rc1:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.4:rc2:*:*:*:*:*:*
  • OR cpe:/a:eggheads:eggdrop_docker_image:1.8.4:rc3:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    eggheads eggdrop docker image 1.6
    eggheads eggdrop docker image 1.6.21
    eggheads eggdrop docker image 1.8.0
    eggheads eggdrop docker image 1.8.0 rc1
    eggheads eggdrop docker image 1.8.0 rc2
    eggheads eggdrop docker image 1.8.0 rc3
    eggheads eggdrop docker image 1.8.0 rc4
    eggheads eggdrop docker image 1.8.1
    eggheads eggdrop docker image 1.8.1 rc2
    eggheads eggdrop docker image 1.8.2
    eggheads eggdrop docker image 1.8.2 rc1
    eggheads eggdrop docker image 1.8.2 rc2
    eggheads eggdrop docker image 1.8.3
    eggheads eggdrop docker image 1.8.3 rc1
    eggheads eggdrop docker image 1.8.4
    eggheads eggdrop docker image 1.8.4 rc1
    eggheads eggdrop docker image 1.8.4 rc2
    eggheads eggdrop docker image 1.8.4 rc3