ZeroHour

CVE-2025-15679

Empty-password flaw re-enables server BMC root account after factory reset

CVSS 4.0
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2025-15679 is a missing/empty-password flaw (CWE-258) in a server BMC (baseboard management controller): under certain circumstances, notably a reset to factory defaults, the BMC's root account becomes active with no password set. After such a reset, anyone who can reach the BMC's login interface can authenticate as root with a blank password. A successful attacker gains full control of the BMC (the CVSS 4.0 vector scores high confidentiality, integrity and availability impact on the vulnerable component), which typically includes remote console, power control and virtual media - a common path to controlling or observing the host server. The advisory does not name the vendor, product or version range, so any server whose BMC firmware exhibits this behavior after a factory reset is potentially affected, and the attack vector is scored as local (AV:L), limiting exposure mainly to operators with access to the BMC interface. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported.

What to do: After any factory-default reset of a BMC, immediately check whether the root account has been enabled and set a strong password before reconnecting the controller to the network, and watch your BMC vendor's advisories for an update addressing CVE-2025-15679. Until patched or reconfigured, restrict BMC management interfaces (web UI, IPMI, Redfish) to trusted management networks and review logs for unauthenticated or blank-password root logins.

Affected
Server BMC (baseboard management controller) firmware
Estimated exposure
unknown (affected vendor and version range not disclosed) — The advisory names no vendor, product or versions, so no installed-base, plugin or internet-scan data can be tied to the flaw; BMCs are widely deployed in enterprise servers but are typically reachable only via dedicated management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

Weakness
CWE-258
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:L/U:Clear

In the news

No ingested article mentions this CVE yet.