← back
CVE-2025-12476criticalCWE-306

Resource Lacking AuthN

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 10epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
In short

A critical flaw in BLU-IC2 and BLU-IC4 (up to version 1.19.5) allows attackers to access protected resources without providing valid credentials. This means sensitive data or functions can be accessed by anyone without authentication.

Technical detail

CWE-306 vulnerability where critical resources lack proper authentication controls in BLU-IC2 and BLU-IC4 versions ≤1.19.5. An unauthenticated attacker can directly access protected endpoints or resources, resulting in unauthorized data exposure and potential system compromise.

Summary generated and translated by AI from the official description.
Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H