logo

Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges

ID: a66868c7-a6c7-54d9-b027-bea9e9e2ae67

STIX ID: report--a66868c7-a6c7-54d9-b027-bea9e9e2ae67

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Executive Summary:** AVEVA disclosed seven vulnerabilities in Process Optimization (<= 2024.1), including a critical unauthenticated API remote code execution (CVE-2025-61937) that permits SYSTEM-level compromise of the taoimr service; other high-severity issues include macro-based code injection, SQL injection granting SQL Server admin access, DLL hijacking, missing ACLs enabling project tampering, and cleartext transmission. AVEVA and CISA coordinated disclosure, and AVEVA recommends immediate upgrade to Process Optimization 2025 or later, restricting taoimr ports (8888/8889), applying strict ACLs, and prioritizing patching to prevent industrial control system compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.