Denial of Service Vulnerability in BLU-IC2 and BLU-IC4 Products from Azure Access
CVE-2025-12601

10CRITICAL

Key Information:

Vendor
CVE Published:
1 November 2025

What is CVE-2025-12601?

A Denial of Service (DoS) vulnerability exists in BLU-IC2 and BLU-IC4 products from Azure Access due to SlowLoris attack exposure. This issue allows an attacker to potentially exhaust connection resources, rendering the affected products unresponsive. Users are advised to take action to mitigate the risks posed by this vulnerability and ensure their systems are secure against such attacks.

Affected Version(s)

BLU-IC2 0 <= 1.19.5

BLU-IC4 0 <= 1.19.5

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Schaller
Benjamin Lafois
Alexi Bitsios
Sebastian Toscano
Dominik Schneider
.
CVE-2025-12601 : Denial of Service Vulnerability in BLU-IC2 and BLU-IC4 Products from Azure Access