CVE-2025-12176: Undocumented Administrative Accounts
Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12176?
The severity of CVE-2025-12176 is considered high due to the creation of undocumented administrative accounts which could lead to unauthorized access.
How do I fix CVE-2025-12176?
To fix CVE-2025-12176, update BLU-IC2 and BLU-IC4 to version 1.19.6 or later to eliminate the vulnerability.
What versions are affected by CVE-2025-12176?
CVE-2025-12176 affects BLU-IC2 and BLU-IC4 versions up to and including 1.19.5.
Can CVE-2025-12176 be exploited remotely?
Yes, CVE-2025-12176 can potentially be exploited remotely due to the presence of undocumented administrative accounts.
Is there a workaround for CVE-2025-12176?
While the recommended solution is to update, it's advised to review and disable any undocumented accounts until the software is updated to mitigate risks from CVE-2025-12176.