Skip to main content

CWE archive

CWE-258 CVEs

Programmatic archive

10 CVEs tagged with CWE-2583 Critical, 4 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-9276

Published Sep 2, 2025

Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on syst…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-4395

Published Jul 24, 2025

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify…

CVSS 6.8 · Medium

CVE-2024-35137

Published Jun 28, 2024

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4106

Published Jun 26, 2024

A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a pas…

CVSS 5.3 · Medium

CVE-2024-28744

Published Apr 8, 2024

The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log…

CVSS 8.8 · High
Showing 1-10 of 10 CVEsPage 1 of 1