CWE-258 · 12 records
Empty Password in Configuration File
CVEs in this class
12 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2019-5021No exploit | Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user.gliderlabs · docker-alpine · CWE-258 | Critical9.8 | — | 6.3% | May 8, 2019 |
40Plan | CVE-2018-17914No exploit | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-258 | Critical9.8 | — | 4.6% | Nov 2, 2018 |
39Monitor | CVE-2023-39439No exploit | SAP Commerce accepts empty passphrases.sap · commerce cloud · CWE-258 | Critical9.8 | — | 0.7% | Aug 7, 2023 |
39Monitor | CVE-2025-9276No exploit | Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerabilitycockroachlabs · cockroach-k8s-request-cert · CWE-258 | Critical9.8 | — | 0.7% | Sep 2, 2025 |
35Monitor | CVE-2024-28744No exploit | The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlifuruno systems co.,ltd. · acera 9010-08 · CWE-258 | High8.8 | — | 0.3% | Apr 7, 2024 |
34Monitor | CVE-2026-84398No exploit | CareCam CM2507 Empty Password in Configuration Filecarecam · hmt.cm2507 firmware · CWE-258 | High8.7 | — | 0.4% | Sep 18, 2026 |
30Monitor | CVE-2020-29478No exploit | CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker broadcom · ca service catalog · CWE-258 | High7.5 | — | 1.2% | Jan 5, 2021 |
29Monitor | CVE-2023-43016No exploit | IBM Security Access Manager Container unauthorized accessibm · security verify access · CWE-258 | High7.3 | — | 0.7% | Feb 2, 2024 |
29Monitor | CVE-2025-15679No exploit | BMC root account active without password on BullSequana XH3406 and XH3515bull · bullsequana xh3406 · CWE-258 | High7.3 | — | 0.1% | Sep 11, 2026 |
27Monitor | CVE-2025-4395No exploit | Medtronic MyCareLink Patient Monitor Empty Password Vulnerabilitymedtronic · mycarelink patient monitor 24950 · CWE-258 | Medium6.8 | — | 0.3% | Jul 24, 2025 |
24Monitor | CVE-2024-35137No exploit | IBM Security Access Manager Docker information disclosureibm · security access manager · CWE-258 | Medium6.2 | — | 0.3% | Jun 28, 2024 |
21Monitor | CVE-2024-4106No exploit | A vulnerability has been found in FAST/TOOLS and CI Server.yokogawa electric corporation · fast/tools · CWE-258 | Medium5.3 | — | 0.4% | Jun 26, 2024 |
- CVE-2019-502141Plan
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user.
CriticalCVSS 9.8No exploitEPSS 6%gliderlabs · docker-alpineMay 8, 2019
- CVE-2018-1791440Plan
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
CriticalCVSS 9.8No exploitEPSS 5%aveva · indusoft web studioNov 2, 2018
- CVE-2023-3943939Monitor
SAP Commerce accepts empty passphrases.
CriticalCVSS 9.8No exploitEPSS 1%sap · commerce cloudAug 7, 2023
- CVE-2025-927639Monitor
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%cockroachlabs · cockroach-k8s-request-certSep 2, 2025
- CVE-2024-2874435Monitor
The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earli
HighCVSS 8.8No exploitEPSS 0%furuno systems co.,ltd. · acera 9010-08Apr 7, 2024
- CVE-2026-8439834Monitor
CareCam CM2507 Empty Password in Configuration File
HighCVSS 8.7No exploitEPSS 0%carecam · hmt.cm2507 firmwareSep 18, 2026
- CVE-2020-2947830Monitor
CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker
HighCVSS 7.5No exploitEPSS 1%broadcom · ca service catalogJan 5, 2021
- CVE-2023-4301629Monitor
IBM Security Access Manager Container unauthorized access
HighCVSS 7.3No exploitEPSS 1%ibm · security verify accessFeb 2, 2024
- CVE-2025-1567929Monitor
BMC root account active without password on BullSequana XH3406 and XH3515
HighCVSS 7.3No exploitEPSS 0%bull · bullsequana xh3406Sep 11, 2026
- CVE-2025-439527Monitor
Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
MediumCVSS 6.8No exploitEPSS 0%medtronic · mycarelink patient monitor 24950Jul 24, 2025
- CVE-2024-3513724Monitor
IBM Security Access Manager Docker information disclosure
MediumCVSS 6.2No exploitEPSS 0%ibm · security access managerJun 28, 2024
- CVE-2024-410621Monitor
A vulnerability has been found in FAST/TOOLS and CI Server.
MediumCVSS 5.3No exploitEPSS 0%yokogawa electric corporation · fast/toolsJun 26, 2024