Critical AVEVA Software Flaws Allow Remote Code Execution With SYSTEM Privileges
ID: eb4c0712-d446-5644-b116-6dd409c653a9
STIX ID: report--eb4c0712-d446-5644-b116-6dd409c653a9
Feed Name: GBHackers
AVEVA has disclosed seven critical and high-severity vulnerabilities in AVEVA Process Optimization (<=2024.1), including an unauthenticated API remote code execution (CVE-2025-61937, CVSS 10.0) that can grant SYSTEM-level access and enable full compromise of the Model Application Server; other critical issues include TCL macro code injection, SQL injection in the Captive Historian, and DLL hijacking. AVEVA recommends immediate upgrade to Process Optimization 2025+ and interim mitigations such as restricting the taoimr service to trusted sources on ports 8888/8889, applying ACLs to installation directories, and enforcing strict chain-of-custody for project files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
