The vulnerability, if exploited, could allow an authenticated miscreant
(Process Optimization Standard User) to tamper with queries in Captive
Historian and achieve code execution under SQL Server administrative
privileges, potentially resulting in complete compromise of the SQL
Server.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aveva
Aveva historian Aveva process Optimization |
|
| Vendors & Products |
Aveva
Aveva historian Aveva process Optimization |
Fri, 16 Jan 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server. | |
| Title | AVEVA Process Optimization SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2026-01-16T00:09:18.629Z
Updated: 2026-01-16T15:06:06.845Z
Reserved: 2025-11-24T18:22:00.776Z
Link: CVE-2025-61943
Updated: 2026-01-16T15:05:37.255Z
Status : Awaiting Analysis
Published: 2026-01-16T02:16:45.093
Modified: 2026-01-16T15:55:12.257
Link: CVE-2025-61943
No data.