CVE-2025-15679
Empty-password flaw re-enables server BMC root account after factory reset
CVE-2025-15679 is a missing/empty-password flaw (CWE-258) in a server BMC (baseboard management controller): under certain circumstances, notably a reset to factory defaults, the BMC's root account becomes active with no password set. After such a reset, anyone who can reach the BMC's login interface can authenticate as root with a blank password. A successful attacker gains full control of the BMC (the CVSS 4.0 vector scores high confidentiality, integrity and availability impact on the vulnerable component), which typically includes remote console, power control and virtual media - a common path to controlling or observing the host server. The advisory does not name the vendor, product or version range, so any server whose BMC firmware exhibits this behavior after a factory reset is potentially affected, and the attack vector is scored as local (AV:L), limiting exposure mainly to operators with access to the BMC interface. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported.
What to do: After any factory-default reset of a BMC, immediately check whether the root account has been enabled and set a strong password before reconnecting the controller to the network, and watch your BMC vendor's advisories for an update addressing CVE-2025-15679. Until patched or reconfigured, restrict BMC management interfaces (web UI, IPMI, Redfish) to trusted management networks and review logs for unauthenticated or blank-password root logins.
| Server BMC (baseboard management controller) firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.
- Weakness
- CWE-258
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:L/U:Clear
In the news0 stories
No ingested article mentions this CVE yet.