← back
CVE-2025-61943

AVEVA Process Optimization SQL Injection

CVSS 9.3 CRITICALEPSS 0.3%CWE-89
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →