IM
IronMonkey Threat Research
‹ Back to ICS Advisories

AVEVA Pipeline Integrity Monitor

HIGH
CVSS 8.4
Date 2026-09-10T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.

// Vulnerabilities (4)

CVE ID CVSS Score Severity Description
CVE-2026-81823 5.3 medium
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.
CVE-2026-81822 8.4 high
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users' app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
CVE-2026-81821 8.4 high
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
CVE-2026-81824 4.7 medium
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.

// Remediations (4)

Patch: Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.
Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.
Patch: AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their oper
AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit: Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files. For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
Patch: Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor
Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.
Mitigation: For more information, see AVEVA security bulletin AVEVA-2026-006. https://www.aveva.com/content/dam/
For more information, see AVEVA security bulletin AVEVA-2026-006. https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf

// References