10
CVE-2025-12275
- EPSS 0.22%
- Veröffentlicht 26.10.2025 16:15:33
- Zuletzt bearbeitet 07.11.2025 02:06:35
- Quelle a0340c66-c385-4f8b-991b-3d05f6
- CVE-Watchlists
- Unerledigt
Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Azure-access ≫ Blu-ic2 Firmware Version < 1.20
Azure-access ≫ Blu-ic4 Firmware Version < 1.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.443 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| a0340c66-c385-4f8b-991b-3d05f6fd5220 | 10 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.