CVE-2025-64691

The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aveva:process_optimization:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:55

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad, si se explota, podría permitir a un malhechor autenticado (usuario estándar del sistema operativo) manipular scripts de macro TCL y escalar privilegios al sistema operativo, lo que podría resultar en un compromiso completo del servidor de aplicaciones del modelo.

22 Jan 2026, 15:15

Type Values Removed Values Added
CPE cpe:2.3:a:aveva:process_optimization:*:*:*:*:*:*:*:*
First Time Aveva process Optimization
Aveva
References () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json - () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json - Third Party Advisory
References () https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea - () https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea - Permissions Required
References () https://www.aveva.com/en/support-and-success/cyber-security-updates/ - () https://www.aveva.com/en/support-and-success/cyber-security-updates/ - Vendor Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01 - Third Party Advisory, US Government Resource

16 Jan 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 02:16

Updated : 2026-06-17 09:55


NVD link : CVE-2025-64691

Mitre link : CVE-2025-64691

CVE.ORG link : CVE-2025-64691


JSON object : View

Products Affected

aveva

  • process_optimization
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')