Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-258

MITRE ↗

CWE-258

3
CRITICAL
4
HIGH
3
MEDIUM
10 CVEs
9.8
CVE-2025-9276

Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability co

6.8
CVE-2025-4395

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with p

8.8
CVE-2024-28744

The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmw

7.3
CVE-2023-43016

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V

6.2
CVE-2024-35137

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileg

5.3
CVE-2024-4106

A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwor

8.8
CVE-2023-39439

SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into

7.5
CVE-2020-29478

CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allo

9.8
CVE-2019-5021

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulne

9.8
CVE-2018-17914

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to

Frequently Asked Questions

What is CWE-258?

CWE-258 (CWE-258) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-258?

There are 10 CVE records associated with CWE-258 in our database. Of these, 3 are critical severity, 4 are high severity, and 3 are medium severity.

How can I protect against CWE-258 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-258 using AI-powered security agents.

Detect CWE-258 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-258 vulnerabilities across your infrastructure.

Get Started