CVE-2025-61937
Severity CVSS v4.0:
CRITICAL
Type:
CWE-94
Code Injection
Publication date:
16/01/2026
Last modified:
16/01/2026
Description
The vulnerability, if exploited, could allow an unauthenticated <br />
miscreant to achieve remote code execution under OS system privileges of<br />
“taoimr” service, potentially resulting in complete compromise of the model application server.
Impact
Base Score 4.0
10.00
Severity 4.0
CRITICAL
Base Score 3.x
10.00
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json
- https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea
- https://www.aveva.com/en/support-and-success/cyber-security-updates/
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01



