CWE-258 · 12 записей
Empty Password in Configuration File
CVE этого класса
12 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2019-5021Эксплойта нет | Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user.gliderlabs · docker-alpine · CWE-258 | Критическая9,8 | — | 6,3 % | 8 мая 2019 г. |
40В плане | CVE-2018-17914Эксплойта нет | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-258 | Критическая9,8 | — | 4,6 % | 2 нояб. 2018 г. |
39Наблюдать | CVE-2023-39439Эксплойта нет | SAP Commerce accepts empty passphrases.sap · commerce cloud · CWE-258 | Критическая9,8 | — | 0,7 % | 7 авг. 2023 г. |
39Наблюдать | CVE-2025-9276Эксплойта нет | Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerabilitycockroachlabs · cockroach-k8s-request-cert · CWE-258 | Критическая9,8 | — | 0,7 % | 2 сент. 2025 г. |
35Наблюдать | CVE-2024-28744Эксплойта нет | The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlifuruno systems co.,ltd. · acera 9010-08 · CWE-258 | Высокая8,8 | — | 0,3 % | 7 апр. 2024 г. |
34Наблюдать | CVE-2026-84398Эксплойта нет | CareCam CM2507 Empty Password in Configuration Filecarecam · hmt.cm2507 firmware · CWE-258 | Высокая8,7 | — | 0,4 % | 18 сент. 2026 г. |
30Наблюдать | CVE-2020-29478Эксплойта нет | CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker broadcom · ca service catalog · CWE-258 | Высокая7,5 | — | 1,2 % | 5 янв. 2021 г. |
29Наблюдать | CVE-2023-43016Эксплойта нет | IBM Security Access Manager Container unauthorized accessibm · security verify access · CWE-258 | Высокая7,3 | — | 0,7 % | 2 февр. 2024 г. |
29Наблюдать | CVE-2025-15679Эксплойта нет | BMC root account active without password on BullSequana XH3406 and XH3515bull · bullsequana xh3406 · CWE-258 | Высокая7,3 | — | 0,1 % | 11 сент. 2026 г. |
27Наблюдать | CVE-2025-4395Эксплойта нет | Medtronic MyCareLink Patient Monitor Empty Password Vulnerabilitymedtronic · mycarelink patient monitor 24950 · CWE-258 | Средняя6,8 | — | 0,3 % | 24 июл. 2025 г. |
24Наблюдать | CVE-2024-35137Эксплойта нет | IBM Security Access Manager Docker information disclosureibm · security access manager · CWE-258 | Средняя6,2 | — | 0,3 % | 28 июн. 2024 г. |
21Наблюдать | CVE-2024-4106Эксплойта нет | A vulnerability has been found in FAST/TOOLS and CI Server.yokogawa electric corporation · fast/tools · CWE-258 | Средняя5,3 | — | 0,4 % | 26 июн. 2024 г. |
- CVE-2019-502141В плане
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %gliderlabs · docker-alpine8 мая 2019 г.
- CVE-2018-1791440В плане
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %aveva · indusoft web studio2 нояб. 2018 г.
- CVE-2023-3943939Наблюдать
SAP Commerce accepts empty passphrases.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sap · commerce cloud7 авг. 2023 г.
- CVE-2025-927639Наблюдать
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cockroachlabs · cockroach-k8s-request-cert2 сент. 2025 г.
- CVE-2024-2874435Наблюдать
The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earli
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %furuno systems co.,ltd. · acera 9010-087 апр. 2024 г.
- CVE-2026-8439834Наблюдать
CareCam CM2507 Empty Password in Configuration File
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %carecam · hmt.cm2507 firmware18 сент. 2026 г.
- CVE-2020-2947830Наблюдать
CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %broadcom · ca service catalog5 янв. 2021 г.
- CVE-2023-4301629Наблюдать
IBM Security Access Manager Container unauthorized access
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %ibm · security verify access2 февр. 2024 г.
- CVE-2025-1567929Наблюдать
BMC root account active without password on BullSequana XH3406 and XH3515
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %bull · bullsequana xh340611 сент. 2026 г.
- CVE-2025-439527Наблюдать
Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
СредняяCVSS 6,8Эксплойта нетEPSS 0 %medtronic · mycarelink patient monitor 2495024 июл. 2025 г.
- CVE-2024-3513724Наблюдать
IBM Security Access Manager Docker information disclosure
СредняяCVSS 6,2Эксплойта нетEPSS 0 %ibm · security access manager28 июн. 2024 г.
- CVE-2024-410621Наблюдать
A vulnerability has been found in FAST/TOOLS and CI Server.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %yokogawa electric corporation · fast/tools26 июн. 2024 г.