AVEVA Pipeline Integrity Monitor

Plan PatchCVSS 8.4ICS-CERT ICSA-26-253-01Sep 10, 2026
AVEVAOil & gas
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

AVEVA Pipeline Integrity Monitor versions up to 2025 SP1 P1 build 7.1.9580.8513 contain vulnerabilities that allow attackers with local access or through browser-based attacks to disclose sensitive information, brute-force password hashes from project files, or execute arbitrary code in user browser sessions. The vulnerabilities stem from weak password hashing algorithms (CWE-321, CWE-327), improper access controls (CWE-862), and cross-site scripting in the PIMBoards web interface (CWE-79). Project files contain encrypted credentials that use legacy hashing vulnerable to brute-force attacks. The vulnerability affects all users who interact with affected project files or access the PIMBoards web interface.

What this means
What could happen
An attacker with local access to the Pipeline Integrity Monitor system could disclose sensitive information, brute-force password hashes, or run arbitrary code in a user's browser session, potentially allowing unauthorized control of pipeline monitoring and integrity data.
Who's at risk
Oil and gas operators using AVEVA Pipeline Integrity Monitor systems should care about this advisory. Anyone managing pipeline monitoring infrastructure, including monitoring operators and engineering staff who access PIMBoards projects, needs to take action. The vulnerability is particularly relevant for organizations with older project files or backups running pre-2025 SP1 P2 versions.
How it could be exploited
An attacker with local access to an affected Pipeline Integrity Monitor system could exploit weak cryptographic protections or access control issues to extract password hashes or information from project files, then brute-force credentials or inject malicious code into the PIMBoards web interface that executes when users interact with it.
Prerequisites
  • Local access to the Pipeline Integrity Monitor system or project files
  • User access to PIMBoards web interface for code injection exploitation
weak cryptographic protectionimproper access controlsstored credentials at riskno authentication required for some attack pathsaffects monitoring and control systems
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
Pipeline Integrity Monitor≤ 2025 SP1 P1 build 7.1.9580.8513Fix available
Remediation & Mitigation
0/5
Do now
0/2
WORKAROUNDRequire all PIMBoards users to change their passwords immediately
HARDENINGImplement stricter read access controls on project files that cannot be migrated (backups, transient copies)
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update
HOTFIXMigrate old PIMBoards project files to AVEVA Pipeline Integrity Monitor 2025 SP1 P2
Long-term hardening
0/1
HARDENINGRestrict local access to Pipeline Integrity Monitor systems to authorized personnel only
API: /api/v1/advisories/89e2a3a5-1e26-4ece-ae2d-03feb803d1d0

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

AVEVA Pipeline Integrity Monitor | CVSS 8.4 - OTPulse