Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability co
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with p
The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmw
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileg
A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwor
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into
CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allo
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulne
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to
Frequently Asked Questions
What is CWE-258?
CWE-258 (CWE-258) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-258?
There are 10 CVE records associated with CWE-258 in our database. Of these, 3 are critical severity, 4 are high severity, and 3 are medium severity.
How can I protect against CWE-258 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-258 using AI-powered security agents.
Detect CWE-258 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-258 vulnerabilities across your infrastructure.
Get Started