CVE-2025-61943

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aveva:process_optimization:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:51

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad, si se explota, podría permitir a un malhechor autenticado (Usuario Estándar de Optimización de Procesos) manipular consultas en Captive Historian y lograr la ejecución de código bajo privilegios administrativos de SQL Server, resultando potencialmente en el compromiso total del SQL Server.

22 Jan 2026, 15:19

Type Values Removed Values Added
CPE cpe:2.3:a:aveva:process_optimization:*:*:*:*:*:*:*:*
References () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json - () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json - Third Party Advisory
References () https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea - () https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea - Permissions Required
References () https://www.aveva.com/en/support-and-success/cyber-security-updates/ - () https://www.aveva.com/en/support-and-success/cyber-security-updates/ - Vendor Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01 - Third Party Advisory, US Government Resource
First Time Aveva process Optimization
Aveva

16 Jan 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 02:16

Updated : 2026-06-17 09:51


NVD link : CVE-2025-61943

Mitre link : CVE-2025-61943

CVE.ORG link : CVE-2025-61943


JSON object : View

Products Affected

aveva

  • process_optimization
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')