CVE-2025-61937: AVEVA Process Optimization Code Injection
The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the model application server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61937?
CVE-2025-61937 has a critical severity rating, as it allows for remote code execution with system privileges.
How do I fix CVE-2025-61937?
To fix CVE-2025-61937, update your AVEVA Process Optimization software to the latest version beyond 2025.
What are the potential consequences of exploiting CVE-2025-61937?
Exploiting CVE-2025-61937 could lead to complete compromise of the model application server, allowing unauthorized command execution.
Who is affected by CVE-2025-61937?
Any users of AVEVA Process Optimization version prior to 2025 are affected by CVE-2025-61937.
Is CVE-2025-61937 exploitable without authentication?
Yes, CVE-2025-61937 can be exploited by unauthenticated users, increasing the risk of remote code execution.