CVE-2025-15679

Summary

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

Affected Software

VendorProductVersion RangeStatus
BullBullSequana XH34060 < TS 04.05affected
BullBullSequana XH35150 < TS 43.01affected

Weaknesses

  • CWE-258: CWE-258 Empty password in configuration file

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References