CVE-2025-15679: BMC root account active without password
Published Sep 11, 2026
·Updated
Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password.
Affected Software
1 affected component
BMC BMC root account
Event History
Sep 11, 2026
CVE Published
via MITRE·08:02 AM
Data Sourced
via MITRE·08:02 AM
RemedyDescriptionWeakness
Frequently Asked Questions
1
When is the BMC root account exposed without a password?
The issue can occur under certain circumstances, including after a reset to factory default operation, when the BMC root account is made active without a password.
2
What should be checked after resetting a BMC to factory defaults?
Verify whether the BMC root account is active and whether a password is configured. If it is active without a password, set a password immediately.