Incomplete in the CWE catalog · 9 CVEs mapped
Using an empty string as a password is insecure.
🚨 A blank root password! That’s the shocking vulnerability behind CVE-2025-9276, letting remote attackers waltz into systems running the Cockroach Labs cockroach-k8s-request-cert container image. 🔥 Think of it like a hotel that forgot to change the master key after check-in — anyone can walk right in without a reservation. This oversight leaves your system exposed to anyone who knows where to look! An attacker can bypass all authentication measures and gain full access to the system, potentially compromising sensitive data or disrupting services. This could lead to absolute chaos, as unauthorized users would have the keys to the kingdom!
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.