CVE-2025-15679: Bull Bullsequana XH3406

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

Affected products

  • Bull Bullsequana XH3406
  • Bull Bullsequana XH3515

Published 2026-09-11. Last modified 2026-09-11.