CVE-2025-4384

The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw.
CVSS

No CVSS.

References
Configurations

No configuration.

History

07 May 2025, 14:13

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-06 16:15

Updated : 2025-05-07 14:13


NVD link : CVE-2025-4384

Mitre link : CVE-2025-4384

CVE.ORG link : CVE-2025-4384


JSON object : View

Products Affected

No product.

CWE
CWE-298

Improper Validation of Certificate Expiration