CVE-2025-64769: AVEVA Process Optimization Cleartext Transmission of Sensitive Information
Published Jan 16, 2026
·Updated
The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspection scenarios.
Affected Software
2 affected components
AVEVA Process Optimization
AVEVA Process Optimization<2025
Remediation
Information
AVEVA recommends users take the following action:
* Update to AVEVA Process Optimization v2025 https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea
For more information, please
AVEVA's security bulletin AVEVA-2026-001 https://www.aveva.com/en/support-and-success/cyber-security-updates/ .
Event History
Jan 16, 2026
CVE Published
via MITRE·12:16 AM
Data Sourced
via MITRE·12:16 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64769?
CVE-2025-64769 has a high severity level due to the risk of cleartext transmission of sensitive information.
2
How do I fix CVE-2025-64769?
To fix CVE-2025-64769, ensure that all connections are configured to use encryption.
3
What are the risks associated with CVE-2025-64769?
The risks include potential hijacking and data leakage during man-in-the-middle attacks or passive network inspections.
4
Which software is affected by CVE-2025-64769?
CVE-2025-64769 affects the AVEVA Process Optimization application suite.
5
How can I mitigate the impact of CVE-2025-64769?
Mitigation can be achieved by implementing secure communication protocols to encrypt sensitive data transmissions.