CVE-2025-65117
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2026-01-16
Last updated on: 2026-01-16
Assigner: ICS-CERT
Description
Description
The vulnerability, if exploited, could allow an authenticated miscreant
(Process Optimization Designer User) to embed OLE objects into graphics,
and escalate their privileges to the identity of a victim user who
subsequently interacts with the graphical elements.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aveva | pi_integrator_for_business_analytics | to 2020_r2_sp1 (exc) |
| aveva | pi_web_api | * |
| aveva | pi_connector_for_cygnet | * |
| aveva | pi_data_archive | * |
| aveva | suitelink_server | * |
| aveva | historian_server | * |
| aveva | pi_af_client | * |
| aveva | edge | * |
| aveva | pi_server | * |
| aveva | operations_control_logger | * |
| aveva | plant_scada | * |
| aveva | telemetry_server | * |
| aveva | in_touch_access_anywhere | * |
| aveva | system_platform | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-676 | The product invokes a potentially dangerous function that could introduce a vulnerability if it is used incorrectly, but the function can also be used safely. |