PatchSiren cyber security CVE debrief
CVE-2025-13084 Opto 22 CVE debrief
CVE-2025-13084 is a high-severity information exposure issue in Opto 22 groov View. According to the CISA advisory, the groov View API users endpoint can return a list of all users and associated metadata, including API keys. The endpoint requires an Editor role, but it can reveal API keys for all users, including Administrators. Opto 22 has released a fix and recommends upgrading affected systems.
- Vendor
- Opto 22
- Product
- groov View Server for Windows
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-11-25
- Original CVE updated
- 2025-11-25
- Advisory published
- 2025-11-25
- Advisory updated
- 2025-11-25
Who should care
Organizations running Opto 22 groov View Server for Windows or GRV-EPIC firmware, especially teams with Editor-role users, administrators, or exposed industrial control system management interfaces.
Technical summary
The advisory describes a users endpoint in the groov View API that discloses user records and associated metadata, including API keys. Access to the endpoint is gated by the Editor role, but successful access can expose keys for all users, including Administrator accounts. The supplied CVSS vector indicates network attackability with low attack complexity, low required privileges, no user interaction, and high confidentiality impact.
Defensive priority
High. This vulnerability can expose privileged API keys and should be addressed promptly wherever groov View is deployed, especially in environments that rely on API keys for administrative or operational access.
Recommended defensive actions
- Upgrade groov View Server for Windows to Version R4.5e.
- Upgrade GRV-EPIC Firmware to Version 4.0.3.
- Review which accounts have the Editor role and limit that role to the smallest necessary set of users.
- Rotate or revoke any API keys that may have been exposed through the endpoint.
- Audit logs and access records for unexpected use of the users endpoint or related administrative activity.
- Validate that affected systems are reachable only from trusted management networks and follow CISA industrial control systems defensive guidance.
Evidence notes
All core claims are taken from the CISA CSAF advisory and its remediation entry. The advisory states that the groov View API users endpoint returns user metadata including API keys and that it requires an Editor role. The remediation section states Opto 22 published a patch and recommends upgrading to groov View Server for Windows Version R4.5e and GRV-EPIC Firmware Version 4.0.3. No exploit steps or unsupported details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-13084 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-13084
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-13084 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13084
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-329-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.