---
id: CVE-2025-15679
title: >-
  Under certain circumstances such as reset to factory default operation, the
  BMC root account is made active without a password on BullSequana XH3406 and
  XH3515.
summary: >-
  Under certain circumstances such as reset to factory default operation, the
  BMC root account is made active without a password on BullSequana XH3406 and
  XH3515.
severity: high
cvss: 7.3
cvssVector: >-
  CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:P/S:P/AU:N/R:U/V:C/RE:L/U:Clear
cwe:
  - CWE-258
vendor: Bull
product: BullSequana XH3406
affected:
  - bullsequana_xh3406 < TS 04.05
  - bullsequana_xh3515 < TS 43.01
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T16:17:04.560'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15679'
references:
  - url: >-
      https://myatos.my.site.com/psmcustomer/s/contentdocument/069ci00000eNzLYAA0
    label: 5bcc34ac-0282-4e8a-96fc-046c583d3048
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T15:23:45.592824Z'
cvssSource: cna
epss: 0.00111
epssPercentile: 0.01204
ingestedAt: '2026-09-11T11:32:42.768Z'
---

## Overview

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
