CWE-258 · 12 kayıt
Empty Password in Configuration File
Bu sınıftaki CVE’ler
12 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-5021İstismar yok | Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user.gliderlabs · docker-alpine · CWE-258 | Kritik9,8 | — | %6,3 | 8 May 2019 |
40Planlayın | CVE-2018-17914İstismar yok | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-258 | Kritik9,8 | — | %4,6 | 2 Kas 2018 |
39İzleyin | CVE-2023-39439İstismar yok | SAP Commerce accepts empty passphrases.sap · commerce cloud · CWE-258 | Kritik9,8 | — | %0,7 | 7 Ağu 2023 |
39İzleyin | CVE-2025-9276İstismar yok | Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerabilitycockroachlabs · cockroach-k8s-request-cert · CWE-258 | Kritik9,8 | — | %0,7 | 2 Eyl 2025 |
35İzleyin | CVE-2024-28744İstismar yok | The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlifuruno systems co.,ltd. · acera 9010-08 · CWE-258 | Yüksek8,8 | — | %0,3 | 7 Nis 2024 |
34İzleyin | CVE-2026-84398İstismar yok | CareCam CM2507 Empty Password in Configuration Filecarecam · hmt.cm2507 firmware · CWE-258 | Yüksek8,7 | — | %0,4 | 18 Eyl 2026 |
30İzleyin | CVE-2020-29478İstismar yok | CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker broadcom · ca service catalog · CWE-258 | Yüksek7,5 | — | %1,2 | 5 Oca 2021 |
29İzleyin | CVE-2023-43016İstismar yok | IBM Security Access Manager Container unauthorized accessibm · security verify access · CWE-258 | Yüksek7,3 | — | %0,7 | 2 Şub 2024 |
29İzleyin | CVE-2025-15679İstismar yok | BMC root account active without password on BullSequana XH3406 and XH3515bull · bullsequana xh3406 · CWE-258 | Yüksek7,3 | — | %0,1 | 11 Eyl 2026 |
27İzleyin | CVE-2025-4395İstismar yok | Medtronic MyCareLink Patient Monitor Empty Password Vulnerabilitymedtronic · mycarelink patient monitor 24950 · CWE-258 | Orta6,8 | — | %0,3 | 24 Tem 2025 |
24İzleyin | CVE-2024-35137İstismar yok | IBM Security Access Manager Docker information disclosureibm · security access manager · CWE-258 | Orta6,2 | — | %0,3 | 28 Haz 2024 |
21İzleyin | CVE-2024-4106İstismar yok | A vulnerability has been found in FAST/TOOLS and CI Server.yokogawa electric corporation · fast/tools · CWE-258 | Orta5,3 | — | %0,4 | 26 Haz 2024 |
- CVE-2019-502141Planlayın
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user.
KritikCVSS 9,8İstismar yokEPSS %6gliderlabs · docker-alpine8 May 2019
- CVE-2018-1791440Planlayın
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
KritikCVSS 9,8İstismar yokEPSS %5aveva · indusoft web studio2 Kas 2018
- CVE-2023-3943939İzleyin
SAP Commerce accepts empty passphrases.
KritikCVSS 9,8İstismar yokEPSS %1sap · commerce cloud7 Ağu 2023
- CVE-2025-927639İzleyin
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1cockroachlabs · cockroach-k8s-request-cert2 Eyl 2025
- CVE-2024-2874435İzleyin
The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earli
YüksekCVSS 8,8İstismar yokEPSS %0furuno systems co.,ltd. · acera 9010-087 Nis 2024
- CVE-2026-8439834İzleyin
CareCam CM2507 Empty Password in Configuration File
YüksekCVSS 8,7İstismar yokEPSS %0carecam · hmt.cm2507 firmware18 Eyl 2026
- CVE-2020-2947830İzleyin
CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker
YüksekCVSS 7,5İstismar yokEPSS %1broadcom · ca service catalog5 Oca 2021
- CVE-2023-4301629İzleyin
IBM Security Access Manager Container unauthorized access
YüksekCVSS 7,3İstismar yokEPSS %1ibm · security verify access2 Şub 2024
- CVE-2025-1567929İzleyin
BMC root account active without password on BullSequana XH3406 and XH3515
YüksekCVSS 7,3İstismar yokEPSS %0bull · bullsequana xh340611 Eyl 2026
- CVE-2025-439527İzleyin
Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
OrtaCVSS 6,8İstismar yokEPSS %0medtronic · mycarelink patient monitor 2495024 Tem 2025
- CVE-2024-3513724İzleyin
IBM Security Access Manager Docker information disclosure
OrtaCVSS 6,2İstismar yokEPSS %0ibm · security access manager28 Haz 2024
- CVE-2024-410621İzleyin
A vulnerability has been found in FAST/TOOLS and CI Server.
OrtaCVSS 5,3İstismar yokEPSS %0yokogawa electric corporation · fast/tools26 Haz 2024