Executive brief
The Baseboard Management Controller (BMC) on Atos BullSequana servers can be left with an active root account that has no password under certain conditions, such as during factory reset operations. An attacker with physical or network access to the BMC management interface could gain unrestricted administrative control of the server hardware, potentially leading to data theft, service disruption, or deployment of persistent malware at the firmware level.
Technical details
This vulnerability involves a default-credentials / weak-authentication issue in the BMC (Baseboard Management Controller) of Atos BullSequana servers. Under specific conditions—particularly during factory reset operations—the root account on the BMC becomes active without a password requirement. The BMC is typically network-accessible for out-of-band management, and physical access to the server may also permit direct authentication. An attacker who gains access to the BMC gains full administrative control over the server hardware, including the ability to monitor, modify, or disable the running operating system without OS-level detection. Patches or configuration guidance from Atos may be available; refer to the vendor advisory for mitigation steps.
Affected products
- Atos BullSequana XH3406 <UNKNOWN>
- Atos BullSequana XH3515 <UNKNOWN>
Timeline
- 2026-09-11: disclosed