Information
The default switch configuration allows usernames that are not password-protected to log in only from the console. It is possible to configure the switch to allow unprotected usernames to log in from any port.
Allowing remote access to accounts without passwords is a severe security risk.
Solution
Reset the feature to the default value
#default aaa authentication policy local allow-nopassword-remote-login