Database/Firmware, BMC & network fabric
BullSequana XH3406/XH3515 BMC: factory reset can leave root enabled with no password
Impact
On these Eviden/Atos BullSequana XH3000-family compute blades, certain operations - the record names reset-to-factory-default - leave the BMC root account active with an empty password. Anyone who can reach the BMC then has full out-of-band control of the node: power, console, virtual media, boot order, and firmware update paths. On a GPU node that means an attacker can reboot or re-image a tenant's blade, attach boot media to load their own host image, or persist below the operating system where nothing on the node can see them. It matters most during the exact lifecycle moments where blades get reset - RMA return, redeploy between tenants, rack bring-up - when the node is assumed clean and is often still cabled to the management network. NVD reports the vector as local (AV:L), so the practical exposure is whoever has BMC console or in-band BMC access at that moment, not the open network.
Who can reach it
Anyone able to reach the BMC of a freshly reset XH3406/XH3515 blade - management VLAN access where the BMC is reachable in-band, or local/console access. No authentication is needed, because the root account has no password.
What to do
Treat every factory-reset or re-provisioned blade as compromised until its BMC root password is set: reset, then immediately set a password before the node is cabled to any shared management network or handed to a tenant, and audit existing blades that have been reset for a passwordless root. The record links only the Atos product-security advisory and states no fixed firmware version, so check that advisory for whether a BMC firmware update exists for your platform - do not assume one does. The mitigation itself costs nothing beyond a BMC login; any firmware update that the advisory does name would take the blade out of service.
References
Related entries
- AMI AptioV UEFI BIOS: A race condition in the BIOS that a skilled local attacker can drive to resource exhaustionCVE-2025-22830 · AMI AptioV UEFI BIOSHigh
- AMI AptioV BIOS (unchecked buffer copy): Buffer copy without size checking in firmware leading to arbitrary codeCVE-2025-22833 · AMI AptioV BIOS (unchecked buffer copy)High
- AMD Secure Processor (ASP) bootloader - buffer overflow: A buffer overflow in the ASP bootloader gives an attacker aCVE-2025-29951 · AMD Secure Processor (ASP) bootloader - buffer overflowHigh
- Linux x86/sev - Secure TSC frequency calculation (TSC_FACTOR): Secure TSC is how an SEV-SNP guest gets a timebaseCVE-2025-38508 · Linux x86/sev - Secure TSC frequency calculation (TSC_FACTOR)High
- IBM Power Systems firmware: guest-partition root can write NVRAM that crashes the host firmware boot stageCVE-2026-17042 · IBM Power Systems host firmware (OpenPOWER NVRAM parsing)High
- Linux kernel (drivers/infiniband/hw/irdma): Queue-depth arithmetic was done in 32 bits, so a tenant passing a hugeCVE-2026-31491 · Linux kernel (drivers/infiniband/hw/irdma)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.