CyberRota Analysis
AI-GeneratedThe vulnerability allows the BMC root account to be activated without a password following a factory reset, potentially granting unauthorized access to critical system controls. This poses a significant security risk, as attackers could exploit this weakness to gain full administrative privileges. Organizations utilizing affected BMC systems should prioritize remediation to safeguard against potential unauthorized access and control.
CVE
CVE-2025-15679
Severity
HIGH
CVSS
7.3
EPSS
0.11%
Original NVD Description
Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.