9.8
CVE-2025-9276
- EPSS 0.56%
- Veröffentlicht 02.09.2025 20:00:51
- Zuletzt bearbeitet 30.01.2026 20:27:48
- Quelle zdi-disclosures@trendmicro.com
- CVE-Watchlists
- Unerledigt
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cockroachlabs ≫ Cockroach-k8s-request-cert Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.677 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| zdi-disclosures@trendmicro.com | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-258 Empty Password in Configuration File
Using an empty string as a password is insecure.