nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-4384 CVE-2025-4384
MEDIUM
Certificate validity not properly verified
Record summary
CVE-2025-4384 has a selected CVSS score of 6.0 (medium).
Description
The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 6, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 16.3.0 | unaffected |
| 16.0 to < 16.2.5 | affected | ||
| 15.0 to < 15.2.12 | affected |
References
2pcvue.comVendor advisory
https://www.pcvue.com/security