CVE-2025-15679
Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:P/S:P/AU:N/R:U/V:C/RE:L/U:Clear
- EPSS probability
- 0.11%
- CWE
- CWE-258
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Bull BullSequana XH3406
- Bull BullSequana XH3515
Weakness type
Related vulnerabilities
- CVE-2019-5021 — Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulne
- CVE-2025-9276 — Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
- CVE-2023-39439 — SAP Commerce accepts empty passphrases.
- CVE-2023-43016 — IBM Security Access Manager Container unauthorized access
- CVE-2025-4395 — Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
- CVE-2024-35137 — IBM Security Access Manager Docker information disclosure
- CVE-2024-4106 — A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwor
- CVE-2018-17914 — InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to