logo

Industrial Alert: Critical RCE in AVEVA Software Rated CVSS 10

ID: b8b04667-b747-564f-9a8c-c5ec3fc19391

STIX ID: report--b8b04667-b747-564f-9a8c-c5ec3fc19391

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-20

Date Updated: 2026-04-23

Author: Ddos

...
...

AVEVA issued a critical security bulletin for Process Optimization (formerly ROMeo) disclosing multiple high-severity vulnerabilities—most notably CVE-2025-61937, an unauthenticated RCE (CVSS 10.0) in the API that can allow remote OS-level compromise of the Model Application Server. Additional issues include macro tampering, SQL injection, DLL hijacking, cleartext transmission, and missing access controls; AVEVA advises immediate upgrade to version 2025 or applying strict mitigations (restricting taoimr service access, locking folders, and protecting project files) until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.