CVE-2025-12477
BaseFortify
Publication date: 2025-10-29
Last updated on: 2025-11-07
Assigner: azure-access
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| azure-access | blu-ic2_firmware | to 1.20 (exc) |
| azure-access | blu-ic2 | * |
| azure-access | blu-ic4_firmware | to 1.20 (exc) |
| azure-access | blu-ic4 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Server Version Disclosure issue affecting BLU-IC2 and BLU-IC4 versions through 1.19.5. It means that the server reveals its version information, which can be used by attackers to identify and exploit known vulnerabilities specific to that version.
How can this vulnerability impact me? :
The impact of this vulnerability is that attackers can gain detailed information about the server version, potentially enabling targeted attacks or exploitation of other vulnerabilities associated with that version. This can lead to increased risk of compromise or unauthorized access.