CWE-258Variant

Empty Password in Configuration File

Incomplete in the CWE catalog · 9 CVEs mapped

9
CVEs mapped
7.3
Median CVSS
What it is

Using an empty string as a password is insecure.

Recent examples
9.8cvss
CVE-2025-9276

Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability

🚨 A blank root password! That’s the shocking vulnerability behind CVE-2025-9276, letting remote attackers waltz into systems running the Cockroach Labs cockroach-k8s-request-cert container image. 🔥 Think of it like a hotel that forgot to change the master key after check-in — anyone can walk right in without a reservation. This oversight leaves your system exposed to anyone who knows where to look! An attacker can bypass all authentication measures and gain full access to the system, potentially compromising sensitive data or disrupting services. This could lead to absolute chaos, as unauthorized users would have the keys to the kingdom!

CRITICAL
1%
epss
6.8cvss
CVE-2025-4395

Medtronic MyCareLink Patient Monitor Empty Password Vulnerability

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025

MEDIUMno explanation yet
0%
epss
6.2cvss
CVE-2024-35137

IBM Security Access Manager Docker information disclosure

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-258
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (1)