CVE-2025-12553: Server Certificate Verification Disabled
Published Oct 31, 2025
·Updated
Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 31, 2025
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12553?
The severity of CVE-2025-12553 is classified as high due to the risk of man-in-the-middle attacks caused by disabled email server certificate verification.
2
How do I fix CVE-2025-12553?
To fix CVE-2025-12553, upgrade both BLU-IC2 and BLU-IC4 to versions higher than 1.19.5 where certificate verification is enabled.
3
What types of attacks can exploit CVE-2025-12553?
CVE-2025-12553 can be exploited by man-in-the-middle attacks, allowing an attacker to intercept and manipulate email communications.
4
Which software is affected by CVE-2025-12553?
CVE-2025-12553 affects BLU-IC2 and BLU-IC4 versions up to and including 1.19.5.
5
Is there a workaround for CVE-2025-12553?
There is no specific workaround for CVE-2025-12553; upgrading to a secure version is the recommended action.