Red Hat Enterprise Linux 9 • Release: 7 Benchmark Date: 05 Jan 2026

CAT II V-258120 RHEL-09-611155

RHEL 9 must not have accounts configured with blank or null passwords.

Documentable No
Rule ID SV-258120r991589_rule
CCI References
CCI-000366

If an account has an empty password, anyone could log in and run commands with the privileges of that account. Accounts with empty passwords should never be used in operational environments.

Check Procedure

Verify that null or blank passwords cannot be used with the following command:

$ sudo awk -F: '!$2 {print $1}' /etc/shadow

If the command returns any results, this is a finding.

Fix Action

Configure all accounts on RHEL 9 to have a password or lock the account with the following commands:

Perform a password reset:

$ sudo passwd [username] 

To lock an account:

$ sudo passwd -l [username]