CVE-2025-61943: AVEVA Process Optimization SQL Injection
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61943?
CVE-2025-61943 is considered a high severity vulnerability as it allows authenticated users to execute code with SQL Server administrative privileges.
How do I fix CVE-2025-61943?
Fixing CVE-2025-61943 involves applying the latest security patches provided by AVEVA for the Process Optimization software.
What types of attacks can CVE-2025-61943 facilitate?
CVE-2025-61943 could facilitate SQL injection attacks, allowing attackers to manipulate queries and gain unauthorized access to system resources.
Who is affected by CVE-2025-61943?
CVE-2025-61943 affects users of AVEVA Process Optimization, particularly those with standard user privileges.
What are the potential impacts of exploiting CVE-2025-61943?
Exploitation of CVE-2025-61943 could lead to significant data breaches and unauthorized control over databases managed by SQL Server.