CVE-2025-12285
10.0
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: a0340c66-c385-4f8b-991b-3d05f6fd5220 (Secondary)
Description
Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected (2)
Products: Azure Access: Blu Ic2 Firmware, Blu Ic4 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.20 |
| Running on/with | Platform Versions |
|---|---|
Azure Access Blu Ic2 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.20 |
| Running on/with | Platform Versions |
|---|---|
Azure Access Blu Ic4 | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-521
Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
References (1)
Source: a0340c66-c385-4f8b-991b-3d05f6fd5220
Vendor Advisory
Timeline
No history available yet.