CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

AVEVA Pipeline Integrity Monitor

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7008

As cited

Copy frozen at (site build).

vulnerabilities

AVEVA Pipeline Integrity Monitor

AVEVA Pipeline Integrity Monitor versions up to 2025_SP1_P1_build_7.1.9580.8513 contain four vulnerabilities affecting critical manufacturing infrastructure worldwide. Attackers could decrypt sensitive data with read access to project files, brute-force weak password hashes to escalate privileges, perform unauthenticated information disclosure, or execute arbitrary JavaScript through social engineering. AVEVA released Security Update 2025 SP1 P2 as a mandatory one-way migration, requiring password resets and stricter access controls for older project files that cannot be upgraded.

Why it matters: Organizations operating AVEVA Pipeline Integrity Monitor in critical manufacturing environments must immediately apply Security Update 2025 SP1 P2 and reset all PIMBoards user passwords; CVE-2026-81821 and CVE-2026-81822 enable local attackers to extract encryption keys and brute-force credentials to gain administrative access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary