CVE-2025-4384: Arcinfo Pcvue

Medium severity, CVSS 6.0. EPSS: 0.1% chance of exploitation in the next 30 days.

The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw.

Affected products

  • Arcinfo Pcvue: from 16.0, before 16.2.5 (fixed in 16.2.5); from 15.0, before 15.2.12 (fixed in 15.2.12)

Published 2025-05-06. Last modified 2026-06-17.