CVE-2025-61943

EUVD-2026-2988
The vulnerability, if exploited, could allow an authenticated miscreant 
(Process Optimization Standard User) to tamper with queries in Captive 
Historian and achieve code execution under SQL Server administrative 
privileges, potentially resulting in complete compromise of the SQL 
Server.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.4 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
icscertCNA
8.4 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N