AVEVA Pipeline Integrity Monitor
AVEVA Pipeline Integrity Monitor versions up to 2025 SP1 P1 build 7.1.9580.8513 contain vulnerabilities that allow attackers with local access or through browser-based attacks to disclose sensitive information, brute-force password hashes from project files, or execute arbitrary code in user browser sessions. The vulnerabilities stem from weak password hashing algorithms (CWE-321, CWE-327), improper access controls (CWE-862), and cross-site scripting in the PIMBoards web interface (CWE-79). Project files contain encrypted credentials that use legacy hashing vulnerable to brute-force attacks. The vulnerability affects all users who interact with affected project files or access the PIMBoards web interface.
- Local access to the Pipeline Integrity Monitor system or project files
- User access to PIMBoards web interface for code injection exploitation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/89e2a3a5-1e26-4ece-ae2d-03feb803d1d0Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.