Machine-generated analysis · WAYSCloud LLM
Versions of AVEVA Pipeline Integrity Monitor up to 2025 SP1 P1 build 7.1.9580.8513 are affected.
Context
The advisory concerns AVEVA Pipeline Integrity Monitor, a software product used in critical manufacturing. It states that multiple vulnerabilities—including a hard-coded cryptographic key, a broken algorithm, missing authorization, and cross-site scripting—could allow information disclosure, hash brute-forcing, or arbitrary code execution in a browser session. One vulnerability (CVE-2026-81821) could let an attacker with read access to PIMBoards project files decrypt sensitive data. The product is deployed worldwide.
Operator considerations
Check: Verify which installations run AVEVA Pipeline Integrity Monitor version <=2025_SP1_P1_build_7.1.9580.8513 and locate any un-migrated PIMBoards project files.
Patch: Apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update.
Isolate: Restrict read access to PIMBoards project files until they are migrated or protected.
Log: Monitor authentication attempts and access to PIMBoards files for unusual activity.
Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.
The following versions of AVEVA Pipeline Integrity Monitor are affected:
AVEVA Pipeline Integrity Monitor
Read the full advisory on CISA →