CWE-258: Empty Password in Configuration File
Using an empty string as a password is insecure.
9 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-9276 — Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
- CVE-2025-4395 — Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
- CVE-2024-4106 — A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwor
Recently published
- CVE-2025-9276 — Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
- CVE-2025-4395 — Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
- CVE-2024-4106 — A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwor