CVE-2025-12553CWE-599

Server Certificate Verification Disabled

Critical · published October 31, 2025

CVSS v4.0
10.0
EPSS
0%
Percentile
10.5
In the wild
Unconfirmed
What it is

🚨 The email server just lost its security glasses! With certificate verification disabled, attackers can easily impersonate legitimate servers. 🔥 Imagine a postal service that delivers mail without checking the sender's identity — a recipe for disaster! Just like sending unsecured packages could result in sensitive information falling into the wrong hands, this vulnerability allows attackers to spoof email communications without any verification. An attacker could send emails from a trusted domain, making phishing and social engineering attacks alarmingly easy. This means sensitive data could be leaked, and organizations could be misled into trusting malicious communications — a nightmare scenario!

Put simply

Imagine a postal service that delivers mail without checking the sender's identity — a recipe for disaster! Just like sending unsecured packages could result in sensitive information falling into the wrong hands, this vulnerability allows attackers to spoof email communications without any verification. This vulnerability in BLU-IC2 and BLU-IC4 versions up to 1.19.5 allows the server to disable certificate verification, leaving the door wide open for attackers to impersonate email servers and intercept communications.

What to do

An attacker could send emails from a trusted domain, making phishing and social engineering attacks alarmingly easy. This means sensitive data could be leaked, and organizations could be misled into trusting malicious communications — a nightmare scenario! Immediately upgrade BLU-IC2 and BLU-IC4 to version 1.19.6 or later to restore certificate verification. Additionally, review your server configurations to ensure proper security measures are in place. You can tackle this! Patch your systems today, and you'll be back to secure communications in no time. 🛡️

The record
Technical detail
CVSS v4.0
10.0 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
0.00205 · 10.5th percentile
Weakness
CWE-599 · Missing Validation of OpenSSL Certificate
Published
2025-10-31T15:48Z
EPSS history
Timeline
  • 31 OCT 15:48Z
    Server Certificate Verification Disabled
    cvelistv5