CVE-2025-61937

CRITICAL

AVEVA Process Optimization < 2025 - Unauthenticated Remote Code Execution via taoimr Service

Title source: llm
STIX 2.1

Description

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the  model application server.

Scores

CVSS v3 10.0
EPSS 0.0151
EPSS Percentile 71.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
aveva/process_optimization < 2025
Published Jan 16, 2026
Tracked Since Feb 18, 2026