CVE-2025-15679
CVE-2025-15679 is a high-severity vulnerability with a CVSS 4.0 base score of 7.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-258.
Key facts
- Severity: High (CVSS 4.0 base score 7.3)
- EPSS exploit prediction: 0% (1st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-258
- Published:
- Last modified:
Description
Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.
Frequently asked questions
- What is CVE-2025-15679?
- Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.
- How severe is CVE-2025-15679?
- CVE-2025-15679 has a CVSS 4.0 base score of 7.3, rated high severity.
- Is CVE-2025-15679 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (1st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2025-15679?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2025-15679 published?
- CVE-2025-15679 was published on 2026-09-11.
References
Other CWE-258 vulnerabilities
- CVE-2025-9276 — Critical (CVSS 9.8): Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability…
- CVE-2019-5021 — Critical (CVSS 9.8): Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This…
- CVE-2018-17914 — Critical (CVSS 9.8): InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior…
- CVE-2024-28744 — High (CVSS 8.8): The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24…
- CVE-2023-39439 — High (CVSS 8.8): SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into…
- CVE-2026-84398 — High (CVSS 7.5): CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An…