Impact
Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515. An attacker who can reach the BMC interface, either locally or remotely, could authenticate as root and gain full administrative control, enabling firmware updates, configuration changes, and potentially lateral movement into the host system. Based on the description, it is inferred that this capability allows the attacker to compromise confidentiality, integrity, and availability.
Affected Systems
The BullSequana XH3406 and XH3515 models. All firmware versions that have not applied the patch described in the Technical State by Bull are affected, regardless of the specific build number. Users should verify that their devices are up‑to‑date with the latest BMC firmware release.
Risk and Exploitability
The CVSS score remains 7.3, indicating high severity. EPSS probability is less than 1%, and the vulnerability is not included in the CISA KEV catalog. Based on the description, it is inferred that if an attacker can trigger the factory‑default reset or otherwise obtain access to the BMC interface, they could exploit the unprotected root account for full administrative control, thereby posing a moderate to high risk until remediation.
OpenCVE Enrichment