CNNVD-202601-2843 Information

CNNVD ID

CNNVD-202601-2843

CVE-2025-64729

  • CNNVD Published: 2026-01-16

Description (Chinese)

AVEVA Process Optimization是英国AVEVA公司的一个实时过程优化软件。 AVEVA Process Optimization存在安全漏洞,该漏洞源于经过身份验证的攻击者可能篡改Process Optimization项目文件并嵌入代码,可能导致权限提升。

Description (English)

AVEVA Production Optimization is a real-time process optimization software for AVEVA. There is a security loophole in AVEVA Access Optimization, which stems from the possibility that an identified assailant may tamper with the Project Optimization project file and embedding the code, which may lead to an increase in privileges.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

剑维软件

Published

2026-01-16

Last Modified

2026-02-24

References

https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea https://www.aveva.com/en/support-and-success/cyber-security-updates/ https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01

Patch

https://www.aveva.com/en/support-and-success/cyber-security-updates/

Share on: