CVE-2025-12364: Weak Password Policy
Published Oct 27, 2025
·Updated
Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU BLU-IC2<1.19.5
BLU BLU-IC4<1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 27, 2025
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12364?
The severity of CVE-2025-12364 is considered high due to the weak password policy that may allow unauthorized access.
2
How do I fix CVE-2025-12364?
To fix CVE-2025-12364, implement a stronger password policy that includes complexity requirements and regular password changes.
3
Which versions are affected by CVE-2025-12364?
CVE-2025-12364 affects BLU-IC2 and BLU-IC4 versions up to and including 1.19.5.
4
What is the potential impact of CVE-2025-12364?
The potential impact of CVE-2025-12364 includes increased risk of unauthorized access and potential data breaches.
5
Is there a workaround for CVE-2025-12364?
A temporary workaround for CVE-2025-12364 is to enforce immediate user awareness for creating stronger passwords until a patch is applied.