PT-2020-17200 · Znc · Znc

Koharin

·

Published

2020-12-08

·

Updated

2020-12-22

·

CVE-2020-29577

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions znc versions prior to 1.7.1-slim
Description The official znc docker images contain a blank password for a root user, which may allow a remote attacker to achieve root access. This issue affects systems using the znc docker container deployed by affected versions of the Docker image.
Recommendations For versions prior to 1.7.1-slim, update to version 1.7.1-slim or later to resolve the issue. As a temporary workaround, consider changing the root password to a secure value until a patch is applied. Restrict access to the znc docker container to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-29577

Affected Products

Znc