Reminds me about the 2002 bug in Debian Unstable where something in PAM incorrectly allowed password-less ssh logins for all the system accounts, because "*" in /etc/passwd was parsed as "empty" instead of "no valid password", so you could ssh in as "nobody" and be greeted with a shell :)
https://www.debian.org/security/2002/dsa-177