Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges
ID: a66868c7-a6c7-54d9-b027-bea9e9e2ae67
STIX ID: report--a66868c7-a6c7-54d9-b027-bea9e9e2ae67
Feed Name: cybersecurityNews.com
**Executive Summary:** AVEVA disclosed seven vulnerabilities in Process Optimization (<= 2024.1), including a critical unauthenticated API remote code execution (CVE-2025-61937) that permits SYSTEM-level compromise of the taoimr service; other high-severity issues include macro-based code injection, SQL injection granting SQL Server admin access, DLL hijacking, missing ACLs enabling project tampering, and cleartext transmission. AVEVA and CISA coordinated disclosure, and AVEVA recommends immediate upgrade to Process Optimization 2025 or later, restricting taoimr ports (8888/8889), applying strict ACLs, and prioritizing patching to prevent industrial control system compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
