CVE-2025-2079
Optigo Networks的Visual BACnet Capture Tool和Visual Networks Capture Tool版本3.1.2rc11存在硬编码密钥漏洞,可能被用于生成有效JWT会话。建议升级至v3.1.3rc8以修复问题。 2025-3-11 08:6:0 Author: claroty.com(查看原文) 阅读量:3 收藏

High Threat

CWE-547 USE OF HARD-CODED, SECURITY-RELEVANT CONSTANTS:

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker to generate valid JWT (JSON Web Token) sessions.

Optigo Networks recommends users to upgrade to the following:

  • Visual BACnet Capture Tool: Version v3.1.3rc8
  • Optigo Visual Networks Capture Tool: Version v3.1.3rc8

Risk Information

Product

Visual BACnet Capture Tool, Visual Networks Capture Tool

Disclosure Policy

Team82 is committed to privately reporting vulnerabilities to affected vendors in a coordinated, timely manner in order to ensure the safety of the cybersecurity ecosystem worldwide. To engage with the vendor and research community, Team82 invites you to download and share our Coordinated Disclosure Policy. Team82 will adhere to this reporting and disclosure process when we discover vulnerabilities in products and services.

Public Email & PGP Key

Team82 has also made its public PGP Key available for the vendor and research community to securely and safely exchange vulnerability and research information with us.


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-2079
如有侵权请联系:admin#unsafe.sh