STIGUI
V-282741CAT II — Medium severitySV-282741r1201203_rule

TOSS 5 must not have accounts configured with blank or null passwords.

Rule version TOSS-05-000357 · STIG v1 · 2026-08-20

Discussion

If an account has an empty password, anyone could log in and run commands with the privileges of that account. Accounts with empty passwords should never be used in operational environments.

Check

Verify null or blank passwords cannot be used using the following command:

$ sudo awk -F: '!$2 {print $1}' /etc/shadow

If the command returns any results, this is a finding.

Fix

Configure all accounts on TOSS 5 to have a password or lock the account using the following commands:

Perform a password reset:

$ sudo passwd [username] 

To lock an account:

$ sudo passwd -l [username]

Identifiers

Group ID
V-282741
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-282741r1201203_rule
Check ID
C-87302r1201201_chk
Fix ID
F-87207r1201202_fix