CVE-2025-8386 PUBLISHED

AVEVA Application Server IDE Basic Cross-site Scripting

Assigner: icscert
Reserved: 30.07.2025 Published: 14.11.2025 Updated: 17.11.2025

The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time operations within the IDE component of Application Server. Run-time components and operations are not affected.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H
CVSS Score: 7.2

Product Status

Vendor AVEVA
Product Application Server
Versions Default: unaffected
  • affected from 0 to Versions 2023 R2 SP1 P02 (incl.)

Solutions

AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users using affected product versions should apply security updates to mitigate the risk of exploit.

All affected versions of the Application Server IDE can be fixed by upgrading to AVEVA System Platform 2023 R2 SP1 P03 https://softwaresupportsp.aveva.com/en-US/downloads/products/details/d32b2534-9601-4beb-ac78-046ca2ef594d  or higher.

The following general defensive measures are recommended:

  • Audit assigned permissions to ensure that only trusted users are added to the "aaConfigTools" OS Group. For additional information on Application Server OS Security groups and accounts, see https://docs.aveva.com/bundle/sp-install/page/738031.html

For more information, see AVEVA's Security Bulletin AVEVA-2025-005 https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2025-005.pdf or AVEVA's bulletins page https://www.aveva.com/en/support-and-success/cyber-security-updates/ .

Credits

  • AVEVA reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-80 CWE