216.73.216.6

CVE-2025-4384

· Published 06/05/2025 16:15 · Modified 06/05/2025 16:15

Labels: CVE-2025-4384 2025-05-0687c8e6ad-f0f5-4ca8-89e2-89f26d6ed932CVE-2025-4384CWE-298

Essential information

Published
06/05/2025 16:15
Modified
06/05/2025 16:15
Author
Creator
CVSS
6.0 MEDIUM (v3) 6.0 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932
NVD
View on NVD

Affected products (CPE)

ProductCPE
pcvue / pcvue cpe:2.3:a:pcvue:pcvue:*:*:*:*:*:*:*:*
pcvue / pcvue mqtt addon cpe:2.3:a:pcvue:pcvue_mqtt_addon:*:*:*:*:*:*:*:*

References