Cyber Resilience

CVE-2025-12176

Azure-Access Blu-Ic2 Firmware ≤ 1.20

Published
24 October 2025
Modified
10 November 2025
Patch / advisory
CVSS Score v4 10.0
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0032 24th percentile
Risk Priority 46 floored blend · peak EPSS

Summary

CVE-2025-12176 is a critical-severity Inclusion of Undocumented Features or Chicken Bits (CWE-1242) vulnerability in Azure-Access Blu-Ic2 Firmware. Its CVSS base score is 10.0 (Critical).

Operationally, ranked at the 24th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to CM-7 (Least Functionality) and SA-15 (Development Process, Standards, and Tools) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-11925Same product: Azure-Access Blu-Ic2
CVE-2025-12001Same product: Azure-Access Blu-Ic2
CVE-2025-12285Same product: Azure-Access Blu-Ic2
CVE-2025-12423Same product: Azure-Access Blu-Ic2
CVE-2025-12218Same product: Azure-Access Blu-Ic2
CVE-2025-12284Same product: Azure-Access Blu-Ic2
CVE-2025-12479Same product: Azure-Access Blu-Ic2
CVE-2025-12517Same product: Azure-Access Blu-Ic2
CVE-2025-12602Same product: Azure-Access Blu-Ic2
CVE-2025-12364Same product: Azure-Access Blu-Ic2

Affected Assets

azure-access
blu-ic2 firmware
≤ 1.20
azure-access
blu-ic4 firmware
≤ 1.20

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V6.3.4

Mitigating Controls (NIST 800-53 r5) AI

Least-functionality configuration can disable or remove non-essential capabilities once discovered, limiting the blast radius of any undocumented chicken bits that remain.

Documented development standards and processes directly require that all device features be specified and recorded, preventing hidden chicken bits from being introduced.

An SDLC that incorporates security requires all features to be captured in requirements and design artifacts, stopping undocumented capabilities from being added.

Security engineering principles applied during design explicitly call for complete, documented functionality and the avoidance of hidden or undeclared mechanisms.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly reduce the chance of embedding chicken bits or hidden functionality.

ID.RA-09 partial match
prevents

Pre-acquisition integrity/authenticity assessment can discover undocumented features before deployment.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing in development and acceptance can uncover undocumented functionality before release.

prevents

Secure development life cycle requires documented design and review, reducing hidden or undocumented features.

prevents

Secure system architecture and engineering principles mandate documented, minimal, and auditable designs, limiting chicken bits.

prevents

Secure coding standards and peer review detect and prohibit undocumented or debug features.

prevents

Change management processes require documented approvals, reducing the chance of hidden features being introduced.

degrades

Configuration management enforces documented, approved configurations, limiting undocumented hardware or firmware features.

References