---
cve: "CVE-2025-61943"
severity: "CRITICAL"
cvss: 9.3
epss: "33%"
vendor: "AVEVA"
kev: false
exploited: false
published: "2026-01-16 02:16:45"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T19:17:44+02:00"
---

# CVE-2025-61943

> 9.3 CRITICAL · 🧪 PoC

## Beschreibung

The vulnerability, if exploited, could allow an authenticated miscreant 
(Process Optimization Standard User) to tamper with queries in Captive 
Historian and achieve code execution under SQL Server administrative 
privileges, potentially resulting in complete compromise of the SQL 
Server.

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.aveva.com/en/support-and-success/cyber-security-updates/>
- <https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01>
- <https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-61943) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
