CVE-2025-4384

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
06/05/2025
Last modified:
15/04/2026

Description

The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly.<br /> <br /> The use of a client certificate reduces the risk for random devices to take advantage of this flaw.

References to Advisories, Solutions, and Tools