CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-61943

CVSS 9.3v4.0pub. 2026-01-16upd. 2026-01-22

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.

🤖 AI Analysis
How it works

An authenticated application user (Standard User) can inject malicious data into queries directed to the Captive Historian component by exploiting a flaw in input data validation. Manipulated SQL queries are executed in the context of a SQL Server administrator account. As a result, an attacker can execute arbitrary commands at the privilege level of the database administrator account, which classifies the vulnerability as RCE.

Impact

An attacker can gain full control over the SQL Server instance, including the ability to read, modify and delete data, as well as execute system commands through database mechanisms (e.g., xp_cmdshell). The consequence may be complete compromise of the database server and process data.

Mitigation & patch

Apply patches available from the vendor according to references — update described in the Aveva support portal (softwaresupportsp.aveva.com) and in CISA advisory ICSA-26-015-01. It is recommended to restrict access to the Captive Historian component only to trusted users and to monitor SQL Server account activity.

Who is affected

Aveva Process Optimization (versions indicated in vendor references — advisory ICSA-26-015-01)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Aveva Process Optimization

    APP
    Aveva
    < 2025
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCESQLi
CWE
References

Related vulnerabilities

CVE-2025-61937CRITICAL10.0PL ✓same product

RCE z uprawnieniami systemowymi w Aveva Process Optimization

CVE-2025-64691CRITICAL9.3PL ✓same product

Privilege escalation przez manipulację skryptami TCL w Aveva Process Optimization

CVE-2025-65118CRITICAL9.3PL ✓same product

Privilege escalation w Aveva Process Optimization (CWE-427)

CVE-2025-64729HIGH8.6same product

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Pro...

CVE-2025-64769HIGH7.6same product

The Process Optimization application suite leverages connection channels/protocols that by-default are not en...