Using an empty string as a password is insecure.
Volume of CVEs assigned to CWE-258 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5021CRITICAL Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced | May 8, 2019 | 9.8 | 35 | NO | NO |
CVE-2025-9276CRITICAL Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on syste | Sep 2, 2025 | 9.8 | 32 | NO | NO |
CVE-2018-17914CRITICAL InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated | Nov 2, 2018 | 9.8 | 32 | NO | NO |
CVE-2023-39439CRITICAL SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase. | Aug 8, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-29478HIGH CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition. | Jan 5, 2021 | 7.5 | 25 | NO | NO |
CVE-2025-4395MEDIUM Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify | Jul 24, 2025 | 6.8 | 24 | NO | NO |
CVE-2024-28744HIGH The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log | Apr 8, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-43016HIGH IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a | Feb 3, 2024 | 7.3 | 20 | NO | NO |
CVE-2024-35137MEDIUM IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. | Jun 28, 2024 | 6.2 | 19 | NO | NO |
CVE-2024-4106MEDIUM A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a pass | Jun 26, 2024 | 5.3 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.