CVE-2025-15679

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

  • Published Sep 11, 2026
  • CVSS 7.3 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2025-15679 at the National Vulnerability Database