Cyber Resilience

CWE · MITRE source

CWE-258Empty Password in Configuration File

Abstraction: Variant · CVEs in our corpus: 10

Using an empty string as a password is insecure.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: full · 6 mapping(s) from 3 framework(s): STIG oracle linux 8 2 (full) · STIG oracle linux 9 2 (mostly) · STIG rhel 7 2 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A07:2025 Authentication Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.AA-03
  • PR.PS-01
  • IA-5 Authenticator Management
  • IA-2 Identification and Authentication (Organizational Users)
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 6 hardening rules · 3 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-5021 8.09.80.06262019-05-08
CVE-2018-17914 7.99.80.04572018-11-02
CVE-2025-9276 7.49.80.00652025-09-02
CVE-2023-39439 6.78.80.00712023-08-08
CVE-2024-28744 6.58.80.00302024-04-08
CVE-2020-29478 6.17.50.01172021-01-05
CVE-2023-43016 5.87.30.00712024-02-03
CVE-2025-4395 5.16.80.00272025-07-24
CVE-2024-35137 4.86.20.00262024-06-28
CVE-2024-4106 4.45.30.00392024-06-26