CVE-2025-15679 PUBLISHED

BMC root account active without password on BullSequana XH3406 and XH3515

Assigner: Bull
Reserved: 04.08.2026 Published: 11.09.2026 Updated: 11.09.2026

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:P/S:P/AU:N/R:U/V:C/RE:L/U:Clear
CVSS Score: 7.3

Product Status

Vendor Bull
Product BullSequana XH3406
Versions Default: unaffected
  • affected from 0 to TS 04.05 (excl.)
Vendor Bull
Product BullSequana XH3515
Versions Default: unaffected
  • affected from 0 to TS 43.01 (excl.)

Affected Configurations

Reset to factory default operation.

Solutions

Apply one of the fixed Technical state mentionned above.

References

Problem Types

  • CWE-258 Empty password in configuration file CWE

Impacts

  • CAPEC-70 Try Common or Default Usernames and Passwords