CVE-2025-64729: AVEVA Process Optimization Missing Authorization
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64729?
CVE-2025-64729 is rated as a critical severity vulnerability due to the potential for privilege escalation and unauthorized access.
How do I fix CVE-2025-64729?
To remediate CVE-2025-64729, ensure that you apply the latest security updates and patches provided by AVEVA for Process Optimization.
What are the potential impacts of exploiting CVE-2025-64729?
Exploitation of CVE-2025-64729 can allow an authenticated user to modify project files, embed malicious code, and escalate privileges.
Who is affected by CVE-2025-64729?
CVE-2025-64729 affects users of AVEVA Process Optimization who have standard user accounts.
What types of attacks can CVE-2025-64729 facilitate?
CVE-2025-64729 can facilitate attacks involving unauthorized modification of files and escalated access to sensitive user privileges.