CVE-2025-61937

CRITICAL

Aveva Process Optimization < 2025 - Code Injection

Title source: rule
STIX 2.1

Description

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the  model application server.

Scores

CVSS v3 10.0
EPSS 0.0010
EPSS Percentile 27.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
aveva/process_optimization < 2025
Published Jan 16, 2026
Tracked Since Feb 18, 2026