Skip to content
Noroxi

CWE-258 · 12 records

Empty Password in Configuration File

CVEs in this class

12 records

  • Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user.

    CriticalCVSS 9.8No exploitEPSS 6%

    gliderlabs · docker-alpineMay 8, 2019

  • InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.

    CriticalCVSS 9.8No exploitEPSS 5%

    aveva · indusoft web studioNov 2, 2018

  • SAP Commerce accepts empty passphrases.

    CriticalCVSS 9.8No exploitEPSS 1%

    sap · commerce cloudAug 7, 2023

  • CVE-2025-9276
    39Monitor

    Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    cockroachlabs · cockroach-k8s-request-certSep 2, 2025

  • The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earli

    HighCVSS 8.8No exploitEPSS 0%

    furuno systems co.,ltd. · acera 9010-08Apr 7, 2024

  • CareCam CM2507 Empty Password in Configuration File

    HighCVSS 8.7No exploitEPSS 0%

    carecam · hmt.cm2507 firmwareSep 18, 2026

  • CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker

    HighCVSS 7.5No exploitEPSS 1%

    broadcom · ca service catalogJan 5, 2021

  • IBM Security Access Manager Container unauthorized access

    HighCVSS 7.3No exploitEPSS 1%

    ibm · security verify accessFeb 2, 2024

  • BMC root account active without password on BullSequana XH3406 and XH3515

    HighCVSS 7.3No exploitEPSS 0%

    bull · bullsequana xh3406Sep 11, 2026

  • CVE-2025-4395
    27Monitor

    Medtronic MyCareLink Patient Monitor Empty Password Vulnerability

    MediumCVSS 6.8No exploitEPSS 0%

    medtronic · mycarelink patient monitor 24950Jul 24, 2025

  • IBM Security Access Manager Docker information disclosure

    MediumCVSS 6.2No exploitEPSS 0%

    ibm · security access managerJun 28, 2024

  • CVE-2024-4106
    21Monitor

    A vulnerability has been found in FAST/TOOLS and CI Server.

    MediumCVSS 5.3No exploitEPSS 0%

    yokogawa electric corporation · fast/toolsJun 26, 2024

All vulnerability classes