Insufficient Password Policy Vulnerability in BLU-IC2 and BLU-IC4 by Azure Access
CVE-2025-12552

6.9MEDIUM

Key Information:

Vendor
CVE Published:
31 October 2025

What is CVE-2025-12552?

The vulnerability pertains to an insufficient password policy in Azure Access's BLU-IC2 and BLU-IC4 products, specifically affecting versions up to 1.19.5. This weakness allows for potential unauthorized access, emphasizing the necessity for organizations to adopt stricter password management practices. Without an effective password policy, systems remain at risk, exposing sensitive user data to potential breaches.

Affected Version(s)

BLU-IC2 0 <= 1.19.5

BLU-IC4 0 <= 1.19.5

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Schaller
Benjamin Lafois
Alexi Bitsios
Sebastian Toscano
Dominik Schneider
.
CVE-2025-12552 : Insufficient Password Policy Vulnerability in BLU-IC2 and BLU-IC4 by Azure Access