CVE-2025-2081 (GCVE-0-2025-2081)
Vulnerability from cvelistv5
Published
2025-03-13 17:00
Modified
2026-08-26 13:43
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-547 - Use of Hard-Coded, Security-Relevant Constants in Optigo Networks Visual BACnet Capture Tool/Optigo Visual Networks Capture Tool
Summary
Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients.
References
| URL | Tags | ||||
|---|---|---|---|---|---|
|
|||||
Impacted products
| Vendor | Product | Version | |||||||
|---|---|---|---|---|---|---|---|---|---|
| Optigo Networks | Visual BACnet Capture Tool |
Version: 3.1.2rc11 |
|||||||
|
|||||||||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-2081",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-13T18:42:48.492300Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-03-13T18:42:58.126Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Visual BACnet Capture Tool",
"vendor": "Optigo Networks",
"versions": [
{
"status": "affected",
"version": "3.1.2rc11"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Optigo Visual Networks Capture Tool",
"vendor": "Optigo Networks",
"versions": [
{
"status": "affected",
"version": "3.1.2rc11"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Tomer Goldschmidt of Claroty Team82"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003e\u003c/p\u003e\n\n\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eOptigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients.\u003c/p\u003e\n\n\u003cp\u003e\u003c/p\u003e"
}
],
"value": "Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-547",
"description": "CWE-547 Use of Hard-Coded, Security-Relevant Constants in Optigo Networks Visual BACnet Capture Tool/Optigo Visual Networks Capture Tool",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T13:43:01.114Z",
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert"
},
"references": [
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-070-02"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eOptigo Networks recommends users to upgrade to the following Ubuntu or Windows versions of Optigo Visual Networks Capture Tool version 3.2.1.80.\u003c/p\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eWindows: https://optigo.zendesk.com/hc/en-us/articles/47648910851725-Optigo-Networks-Capture-Tool-Windows-3-2-1-80-Current-Version\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eLinux: https://optigo.zendesk.com/hc/en-us/articles/47649041422861-Optigo-Networks-Capture-Tool-Linux-Ubuntu-3-2-1-80-Current-Version (Ubuntu - Intel \u0026amp; ARM)\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e"
}
],
"value": "Optigo Networks recommends users to upgrade to the following Ubuntu or Windows versions of Optigo Visual Networks Capture Tool version 3.2.1.80.\n\n * \n\nWindows: https://optigo.zendesk.com/hc/en-us/articles/47648910851725-Optigo-Networks-Capture-Tool-Windows-3-2-1-80-Current-Version\n\n\n * \n\nLinux: https://optigo.zendesk.com/hc/en-us/articles/47649041422861-Optigo-Networks-Capture-Tool-Linux-Ubuntu-3-2-1-80-Current-Version (Ubuntu - Intel \u0026 ARM)"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Use of Hard-Coded, Security-Relevant Constants",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"cveId": "CVE-2025-2081",
"datePublished": "2025-03-13T17:00:03.146Z",
"dateReserved": "2025-03-06T22:01:49.726Z",
"dateUpdated": "2026-08-26T13:43:01.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-2081\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"yes\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-03-13T18:42:48.492300Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-03-13T18:42:54.175Z\"}}], \"cna\": {\"title\": \"Use of Hard-Coded, Security-Relevant Constants\", \"source\": {\"discovery\": \"UNKNOWN\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Tomer Goldschmidt of Claroty Team82\"}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV4_0\": {\"Safety\": \"NOT_DEFINED\", \"version\": \"4.0\", \"Recovery\": \"NOT_DEFINED\", \"baseScore\": 8.7, \"Automatable\": \"NOT_DEFINED\", \"attackVector\": \"NETWORK\", \"baseSeverity\": \"HIGH\", \"valueDensity\": \"NOT_DEFINED\", \"vectorString\": \"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\", \"exploitMaturity\": \"NOT_DEFINED\", \"providerUrgency\": \"NOT_DEFINED\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"attackRequirements\": \"NONE\", \"privilegesRequired\": \"NONE\", \"subIntegrityImpact\": \"NONE\", \"vulnIntegrityImpact\": \"NONE\", \"subAvailabilityImpact\": \"NONE\", \"vulnAvailabilityImpact\": \"HIGH\", \"subConfidentialityImpact\": \"NONE\", \"vulnConfidentialityImpact\": \"NONE\", \"vulnerabilityResponseEffort\": \"NOT_DEFINED\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"Optigo Networks\", \"product\": \"Visual BACnet Capture Tool\", \"versions\": [{\"status\": \"affected\", \"version\": \"3.1.2rc11\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Optigo Networks\", \"product\": \"Optigo Visual Networks Capture Tool\", \"versions\": [{\"status\": \"affected\", \"version\": \"3.1.2rc11\"}], \"defaultStatus\": \"unaffected\"}], \"solutions\": [{\"lang\": \"en\", \"value\": \"Optigo Networks recommends users to upgrade to the following Ubuntu or Windows versions of Optigo Visual Networks Capture Tool version 3.2.1.80.\\n\\n * \\n\\nWindows: https://optigo.zendesk.com/hc/en-us/articles/47648910851725-Optigo-Networks-Capture-Tool-Windows-3-2-1-80-Current-Version\\n\\n\\n * \\n\\nLinux: https://optigo.zendesk.com/hc/en-us/articles/47649041422861-Optigo-Networks-Capture-Tool-Linux-Ubuntu-3-2-1-80-Current-Version (Ubuntu - Intel \u0026 ARM)\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eOptigo Networks recommends users to upgrade to the following Ubuntu or Windows versions of Optigo Visual Networks Capture Tool version 3.2.1.80.\u003c/p\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eWindows: https://optigo.zendesk.com/hc/en-us/articles/47648910851725-Optigo-Networks-Capture-Tool-Windows-3-2-1-80-Current-Version\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eLinux: https://optigo.zendesk.com/hc/en-us/articles/47649041422861-Optigo-Networks-Capture-Tool-Linux-Ubuntu-3-2-1-80-Current-Version (Ubuntu - Intel \u0026amp; ARM)\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\", \"base64\": false}]}], \"references\": [{\"url\": \"https://www.cisa.gov/news-events/ics-advisories/icsa-25-070-02\", \"tags\": [\"government-resource\"]}], \"x_generator\": {\"engine\": \"Vulnogram 0.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003e\u003c/p\u003e\\n\\n\u003cp\u003e\\n\\n\u003c/p\u003e\u003cp\u003eOptigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients.\u003c/p\u003e\\n\\n\u003cp\u003e\u003c/p\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-547\", \"description\": \"CWE-547 Use of Hard-Coded, Security-Relevant Constants in Optigo Networks Visual BACnet Capture Tool/Optigo Visual Networks Capture Tool\"}]}], \"providerMetadata\": {\"orgId\": \"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6\", \"shortName\": \"icscert\", \"dateUpdated\": \"2026-08-26T13:43:01.114Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2025-2081\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-26T13:43:01.114Z\", \"dateReserved\": \"2025-03-06T22:01:49.726Z\", \"assignerOrgId\": \"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6\", \"datePublished\": \"2025-03-13T17:00:03.146Z\", \"assignerShortName\": \"icscert\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…