CVE-2025-12601
BaseFortify
Publication date: 2025-11-01
Last updated on: 2025-11-10
Assigner: azure-access
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| azure-access | blu-ic2_firmware | to 1.20 (exc) |
| azure-access | blu-ic2 | * |
| azure-access | blu-ic4_firmware | to 1.20 (exc) |
| azure-access | blu-ic4 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo | |
| CWE-730 |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Denial of Service (DoS) caused by a SlowLoris attack affecting BLU-IC2 and BLU-IC4 devices up to version 1.19.5. SlowLoris is a type of attack that holds connections open by sending partial requests slowly, exhausting server resources and preventing legitimate users from accessing the service.
How can this vulnerability impact me? :
The impact of this vulnerability is a complete Denial of Service, meaning the affected devices can become unresponsive or unavailable to legitimate users, potentially disrupting business operations or critical services.