ZeroHour
Product

AVEVA Pipeline Integrity Monitor

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

AVEVA Pipeline Integrity Monitor

CISA advisory details four flaws in AVEVA Pipeline Integrity Monitor <=2025_SP1_P1, allowing information disclosure, weak-hash admin elevation, and cross-site scripting.

CISA published ICSA-26-253-01 covering AVEVA Pipeline Integrity Monitor versions <=2025_SP1_P1_build_7.1.9580.8513. CVE-2026-81821 (hard-coded cryptographic key, CWE-321) lets a user with read access decrypt PIMBoards project files, and CVE-2026-81822 (CWE-327) allows brute-forcing weak password hashes to elevate to PIMBoards administrator; both score 8.4 HIGH (CVSS v3.1). CVE-2026-81823 (CWE-862) permits unauthenticated read operations, and CVE-2026-81824 (CWE-79) enables arbitrary JavaScript execution via socially engineered links. CISA reports no known public exploitation and recommends limiting network exposure of control system devices.

Related CVEs

  • Weak Password Hashing in PIMBoards Enables Local Brute-Force Privilege Escalation
    CVE-2026-81822 is a weak-cryptography flaw (CWE-327) in PIMBoards: users' app-native passwords are stored in project files using a hashing scheme susceptible to computational brute-forcing. An attacker who gains read access to PIMBoards project files (rated as a local attack vector requiring only low privileges and no user interaction) can extract the stored hashes and crack them offline. Recovering a password can potentially elevate the attacker to a PIMBoards administrator account, with high confidentiality impact on the system and subsequent systems per the CVSS 4.0 vector. Any deployment where unauthorized users, shared storage, or backups expose PIMBoards project files is affected; the source data does not specify affected versions or ranges. There is no known exploitation: the flaw has a 0.1% EPSS score (1st percentile), no public proof-of-concept, and is not listed in CISA KEV.
    · PIMBoards
  • Hard-Coded Cryptographic Key in PIMBoards Exposes Sensitive Data in Project Files
    CVE-2026-81821 is a cryptographic weakness in PIMBoards (CWE-321, use of a hard-coded cryptographic key) that leaves data stored in its project files protected only by encryption that anyone can defeat. It is triggered when an attacker with read access to PIMBoards project files — local access per the CVSS 4.0 vector (AV:L with low privileges, no user interaction required) — obtains those files and decrypts them using the embedded key. The attacker gains the ability to decrypt and read sensitive information in the files; the CVSS 4.0 score rates the direct confidentiality impact as High with no direct integrity or availability impact, though subsequent-system confidentiality and integrity impacts are rated High. Users who store PIMBoards project files in locations readable by other users, accounts, or systems are affected, and the source data does not name a vendor or specify affected versions. There are no known public proof-of-concept exploits, no CISA KEV listing, and a low EPSS probability of 0.1%, so exploitation is not currently known to be occurring.
    · PIMBoards
  • Unauthenticated information disclosure in AVEVA Pipeline Integrity Monitor
    CVE-2026-81823 is a missing-authorization flaw (CWE-862) in AVEVA Pipeline Integrity Monitor that allows an unauthenticated remote attacker to invoke read operations intended only for PIMBoards users. It is triggered by sending unauthenticated network requests to the affected read-only functionality, with no special conditions or user interaction required (CVSS 4.0 vector: AV:N/AC:L/AT:N/PR:N/UI:N). A successful exploit yields information disclosure of data readable through PIMBoards; write operations are explicitly not impacted, so attackers cannot modify data through this flaw. At-risk deployments are installations of AVEVA Pipeline Integrity Monitor where the PIMBoards interface is reachable by untrusted network users, a profile typical of pipeline operators' OT environments. No exploitation is currently known: there is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS estimates a 0.3% probability of exploitation in the next 30 days (24th percentile).
    · AVEVA (Schneider Electric) Pipeline Integrity Monitorniche
  • Cross-Site Scripting (XSS) in AVEVA Pipeline Integrity Monitor PIMBoards
    CVE-2026-81824 is a cross-site scripting flaw (CWE-79) in PIMBoards, the dashboard/boards component of AVEVA Pipeline Integrity Monitor. An attacker must socially engineer an authenticated PIMBoards user into clicking a malicious link, which then causes attacker-controlled JavaScript to run inside that user's browser session. Successful exploitation would let the attacker act within the victim's session, and the CVSS 4.0 vector's high integrity and availability impacts on subsequent systems indicate the injected script could take actions affecting connected or downstream systems. Only users of the PIMBoards component of Pipeline Integrity Monitor who follow a malicious link are affected; unexposed or unattended deployments face little risk. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.3% (22nd percentile), so exploitation is not currently observed.
    · AVEVA Pipeline Integrity Monitor - PIMBoards componentniche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.