The users endpoint in the groov View API returns a list of all users and
associated metadata including their API keys. This endpoint requires an
Editor role to access and will display API keys for all users,
including Administrators.
Advisories

No advisories yet.

Fixes

Solution

Opto 22 has published a patch to address this vulnerability and recommends that users upgrade to groov View Server for Windows Version R4.5e and GRV-EPIC Firmware Version 4.0.3. Additional information is available from Opto 22 here https://www.opto22.com/support/resources-tools/knowledgebase/kb91325 .


Workaround

No workaround given by the vendor.

History

Wed, 26 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Nov 2025 17:45:00 +0000

Type Values Removed Values Added
Description The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
Title Opto 22 groov View Exposure of Sensitive Information Through Metadata
First Time appeared Opto 22
Opto 22 groov View Server
Opto 22 grv-epic-pr1 Firmware
Opto 22 grv-epic-pr2 Firmware
Weaknesses CWE-1230
CPEs cpe:2.3:a:opto_22:groov_view_server:*:*:windows:*:*:*:*:*
cpe:2.3:a:opto_22:grv-epic-pr1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:opto_22:grv-epic-pr2_firmware:*:*:*:*:*:*:*:*
Vendors & Products Opto 22
Opto 22 groov View Server
Opto 22 grv-epic-pr1 Firmware
Opto 22 grv-epic-pr2 Firmware
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-26T18:59:31.021Z

Reserved: 2025-11-12T19:21:15.811Z

Link: CVE-2025-13084

cve-icon Vulnrichment

Updated: 2025-11-26T18:59:22.461Z

cve-icon NVD

Status : Received

Published: 2025-11-26T18:15:47.887

Modified: 2025-11-26T18:15:47.887

Link: CVE-2025-13084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.