CVE-2025-12478: Non-Compliant TLS Configuration
Published Oct 29, 2025
·Updated
Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 29, 2025
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12478?
CVE-2025-12478 has been classified as a high severity due to its potential impact on secure communications.
2
How do I fix CVE-2025-12478?
To resolve CVE-2025-12478, update BLU IC2 and BLU IC4 to versions 1.19.6 or later.
3
What are the potential risks associated with CVE-2025-12478?
CVE-2025-12478 can lead to interception of sensitive data due to non-compliant TLS configurations.
4
Which versions of BLU products are affected by CVE-2025-12478?
CVE-2025-12478 affects BLU IC2 and BLU IC4 versions up to and including 1.19.5.
5
Is there a workaround for CVE-2025-12478 while waiting for a patch?
There are no recommended workarounds for CVE-2025-12478; upgrading to the latest version is advised.