Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart file, sets the root user password to empty, which allows local users to gain privileges.
https://exchange.xforce.ibmcloud.com/vulnerabilities/84488
https://bugzilla.redhat.com/show_bug.cgi?id=964299
http://www.securityfocus.com/bid/60119