CVE-2025-12217
BaseFortify
Publication date: 2025-10-25
Last updated on: 2025-11-10
Assigner: azure-access
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| azure-access | blu-ic2_firmware | to 1.20 (exc) |
| azure-access | blu-ic2 | * |
| azure-access | blu-ic4_firmware | to 1.20 (exc) |
| azure-access | blu-ic4 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1392 | The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the use of a default SNMP community string "public" in affected BLU-IC2 and BLU-IC4 devices up to version 1.19.5. The default community string is a well-known value that can allow unauthorized users to access SNMP data on the device, potentially exposing sensitive information or allowing unauthorized configuration changes.
How can this vulnerability impact me? :
An attacker who exploits this vulnerability could gain unauthorized access to SNMP data on the affected devices, which may lead to information disclosure or unauthorized device configuration changes. This could compromise the security and integrity of the affected systems.