VYPR

Application Server

by Aveva

CVEs (8)

  • CVE-2025-61937CriJan 16, 2026
    risk 0.65cvss 10.0epss 0.02

    The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the  model application server.

  • CVE-2025-65118HigJan 16, 2026
    risk 0.57cvss 8.8epss 0.00

    The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.

  • CVE-2025-64691HigJan 16, 2026
    risk 0.57cvss 8.8epss 0.00

    The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server.

  • CVE-2023-33873HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.

  • CVE-2025-8386MedNov 15, 2025
    risk 0.45cvss 6.9epss 0.00

    The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical …

  • CVE-2023-34982MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.00

    This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

  • CVE-2012-0258Apr 2, 2012
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and…

  • CVE-2010-2974Aug 5, 2010
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment…