VYPR
advisoryPublished Sep 10, 2026· 1 source

CISA Flags Multiple Critical Vulnerabilities in AVEVA Pipeline Integrity Monitor

CISA has issued an advisory detailing four critical vulnerabilities in AVEVA Pipeline Integrity Monitor, potentially allowing attackers to disclose sensitive information, brute-force passwords, or execute arbitrary code.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory concerning multiple vulnerabilities within AVEVA Pipeline Integrity Monitor, versions up to and including 2025 SP1 P1 build 7.1.9580.8513. These flaws, identified under CVE-2026-81821 through CVE-2026-81824, pose significant risks to industrial control systems, particularly within the critical manufacturing sector.

The vulnerabilities stem from several weaknesses in the software's design, including the use of hard-coded cryptographic keys, weak hashing algorithms for password storage, missing authorization checks, and susceptibility to cross-site scripting (XSS) attacks. Successful exploitation could grant attackers unauthorized access to sensitive data, enable brute-force attacks against user credentials, or allow for the execution of malicious code within a user's browser session.

Specifically, CVE-2026-81821 involves a hard-coded cryptographic key that, if exploited by an attacker with read access to project files, could allow for the decryption and exposure of sensitive information. This could include configuration details, operational parameters, or other proprietary data critical to pipeline integrity management.

CVE-2026-81822 addresses the use of a broken or risky cryptographic algorithm for password hashing. This weakness could enable an attacker to reverse-engineer user passwords by computationally brute-forcing the weak hashes, potentially leading to the elevation of privileges to an administrator level within the PIMBoards system.

Furthermore, CVE-2026-81823 highlights a missing authorization flaw, allowing unauthenticated attackers to perform read operations that are normally restricted to authenticated PIMBoards users. While write operations remain unaffected, this vulnerability could still lead to significant information disclosure.

Finally, CVE-2026-81824 points to a cross-site scripting (XSS) vulnerability. This flaw could allow an attacker to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, credential theft, or the execution of arbitrary code in the context of the victim's browser session.

AVEVA has released a security update, AVEVA Pipeline Integrity Monitor 2025 SP1 P2, to address these vulnerabilities. The company strongly recommends that customers apply this update and migrate their old project files. For project files that cannot be migrated, AVEVA advises implementing stricter read access controls to mitigate the risk of password leakage. Users are also urged to change their passwords immediately. The migration process to the updated version is a one-way process due to changes in password hashing algorithms and encryption key management.

These vulnerabilities carry high severity ratings, with CVSS v3.1 scores reaching 8.4 (HIGH). The potential impact on critical infrastructure, coupled with the worldwide deployment of AVEVA Pipeline Integrity Monitor, underscores the urgency for organizations to apply the provided patches and follow the recommended mitigation steps to protect their operational environments.

Synthesized by Vypr AI