CVE-2025-12365: Error Messages Wrapped In HTTP Header
Published Oct 27, 2025
·Updated
Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU BLU-IC2<=1.19.5
BLU BLU-IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 27, 2025
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12365?
CVE-2025-12365 is rated as a medium severity vulnerability due to the potential exposure of error messages in HTTP headers.
2
How do I fix CVE-2025-12365?
To remediate CVE-2025-12365, upgrade your BLU-IC2 or BLU-IC4 to version 1.19.6 or later.
3
What products are affected by CVE-2025-12365?
CVE-2025-12365 affects BLU-IC2 and BLU-IC4 versions up to and including 1.19.5.
4
Is there any risk associated with not addressing CVE-2025-12365?
Failing to address CVE-2025-12365 can lead to information disclosure through sensitive error messages visible in HTTP headers.
5
Where can I find more information about CVE-2025-12365?
For further details on CVE-2025-12365, refer to security advisories issued by BLU.