logo

Critical AVEVA Software Flaws Allow Remote Code Execution With SYSTEM Privileges

ID: eb4c0712-d446-5644-b116-6dd409c653a9

STIX ID: report--eb4c0712-d446-5644-b116-6dd409c653a9

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Divya

...
...

AVEVA has disclosed seven critical and high-severity vulnerabilities in AVEVA Process Optimization (<=2024.1), including an unauthenticated API remote code execution (CVE-2025-61937, CVSS 10.0) that can grant SYSTEM-level access and enable full compromise of the Model Application Server; other critical issues include TCL macro code injection, SQL injection in the Captive Historian, and DLL hijacking. AVEVA recommends immediate upgrade to Process Optimization 2025+ and interim mitigations such as restricting the taoimr service to trusted sources on ports 8888/8889, applying ACLs to installation directories, and enforcing strict chain-of-custody for project files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.