CVE-2025-61943

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aveva:process_optimization:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-16 02:16

Updated : 2026-01-22 15:19


NVD link : CVE-2025-61943

Mitre link : CVE-2025-61943

CVE.ORG link : CVE-2025-61943


JSON object : View

Products Affected

aveva

  • process_optimization
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')