AVEVA Process Optimization Privilege Escalation Vulnerability
Vulnerability
A vulnerability in AVEVA Process Optimization (formerly ROMeo) versions through 2024.1 has been identified, allowing an authenticated user to manipulate the Process Optimization services into executing arbitrary code. This exploitation could escalate privileges to the operating system level, potentially leading to a complete compromise of the Model Application Server.
Impact
Exploitation of this vulnerability could allow an authenticated user to execute arbitrary code with elevated privileges, potentially compromising the entire Model Application Server.
Remediation
Users can refer to the AVEVA Security Bulletin AVEVA-2026-001 for guidance on applying the security update. This bulletin is available on the AVEVA website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
