The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.
An authenticated application user (Standard User) can inject malicious data into queries directed to the Captive Historian component by exploiting a flaw in input data validation. Manipulated SQL queries are executed in the context of a SQL Server administrator account. As a result, an attacker can execute arbitrary commands at the privilege level of the database administrator account, which classifies the vulnerability as RCE.
An attacker can gain full control over the SQL Server instance, including the ability to read, modify and delete data, as well as execute system commands through database mechanisms (e.g., xp_cmdshell). The consequence may be complete compromise of the database server and process data.
Apply patches available from the vendor according to references — update described in the Aveva support portal (softwaresupportsp.aveva.com) and in CISA advisory ICSA-26-015-01. It is recommended to restrict access to the Captive Historian component only to trusted users and to monitor SQL Server account activity.
Aveva Process Optimization (versions indicated in vendor references — advisory ICSA-26-015-01)
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAveva Process Optimization
APPAveva< 2025
Related vulnerabilities
RCE z uprawnieniami systemowymi w Aveva Process Optimization
Privilege escalation przez manipulację skryptami TCL w Aveva Process Optimization
Privilege escalation w Aveva Process Optimization (CWE-427)
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Pro...
The Process Optimization application suite leverages connection channels/protocols that by-default are not en...