The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server.
The vulnerability classified as CWE-94 (Code Injection) allows an authenticated but unprivileged operating system user to modify TCL Macro scripts in the application. The manipulated scripts are then executed in the context of higher privileges, leading to privilege escalation from the level of an ordinary OS user to system level (OS system). The attack vector is local, does not require user interaction or special preconditions beyond having a standard OS account.
An attacker can obtain system privileges on the host, resulting in complete takeover of the model application server, including full control over data, configuration, and industrial processes handled by the application.
Apply patches available from the vendor according to references (Aveva support portal: softwaresupportsp.aveva.com and security updates page aveva.com). It is also recommended to restrict local system access exclusively to trusted, necessary user accounts and to monitor changes in TCL Macro scripts.
Aveva Process Optimization — versions indicated in vendor references
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAveva Process Optimization
APPAveva< 2025
Related vulnerabilities
RCE z uprawnieniami systemowymi w Aveva Process Optimization
SQL Injection w Aveva Process Optimization umożliwiający RCE
Privilege escalation w Aveva Process Optimization (CWE-427)
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Pro...
The Process Optimization application suite leverages connection channels/protocols that by-default are not en...