CVE-2025-2080: Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that...

9.3 CVSS

Description

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker to bypass authentication measures and gain controls over utilities within the products.

Classification

CVE ID: CVE-2025-2080

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.3

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem Types

CWE-288 Authentication Bypass Using an Alternate Path or Channel

Affected Products

Vendor: Optigo Networks, Optigo Networks

Product: Visual BACnet Capture Tool, Optigo Visual Networks Capture Tool

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 16.88% (scored less or equal to compared to others)

EPSS Date: 2025-04-11 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-2080
https://www.cisa.gov/news-events/ics-advisories/icsa-25-070-02

Timeline