All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2025-61937
CRITICALpublished 2026-01-16 02:16 UTC · 7 months ago · modified 2026-06-17 09:51 UTC
10.0
CVSS / 10
// description
The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the model application server.
// weaknesses (CWE)
- CWE-94
// references (4)
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json
- https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea
- https://www.aveva.com/en/support-and-success/cyber-security-updates/
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01