PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-13084 Opto 22 CVE debrief

CVE-2025-13084 is a high-severity information exposure issue in Opto 22 groov View. According to the CISA advisory, the groov View API users endpoint can return a list of all users and associated metadata, including API keys. The endpoint requires an Editor role, but it can reveal API keys for all users, including Administrators. Opto 22 has released a fix and recommends upgrading affected systems.

Vendor
Opto 22
Product
groov View Server for Windows
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2025-11-25
Original CVE updated
2025-11-25
Advisory published
2025-11-25
Advisory updated
2025-11-25

Who should care

Organizations running Opto 22 groov View Server for Windows or GRV-EPIC firmware, especially teams with Editor-role users, administrators, or exposed industrial control system management interfaces.

Technical summary

The advisory describes a users endpoint in the groov View API that discloses user records and associated metadata, including API keys. Access to the endpoint is gated by the Editor role, but successful access can expose keys for all users, including Administrator accounts. The supplied CVSS vector indicates network attackability with low attack complexity, low required privileges, no user interaction, and high confidentiality impact.

Defensive priority

High. This vulnerability can expose privileged API keys and should be addressed promptly wherever groov View is deployed, especially in environments that rely on API keys for administrative or operational access.

Recommended defensive actions

  • Upgrade groov View Server for Windows to Version R4.5e.
  • Upgrade GRV-EPIC Firmware to Version 4.0.3.
  • Review which accounts have the Editor role and limit that role to the smallest necessary set of users.
  • Rotate or revoke any API keys that may have been exposed through the endpoint.
  • Audit logs and access records for unexpected use of the users endpoint or related administrative activity.
  • Validate that affected systems are reachable only from trusted management networks and follow CISA industrial control systems defensive guidance.

Evidence notes

All core claims are taken from the CISA CSAF advisory and its remediation entry. The advisory states that the groov View API users endpoint returns user metadata including API keys and that it requires an Editor role. The remediation section states Opto 22 published a patch and recommends upgrading to groov View Server for Windows Version R4.5e and GRV-EPIC Firmware Version 4.0.3. No exploit steps or unsupported details are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-13084 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-13084

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-13084 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13084

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-329-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.