As cited
Copy frozen at (site build).
vulnerabilities
AVEVA Pipeline Integrity Monitor
AVEVA Pipeline Integrity Monitor versions up to 2025_SP1_P1_build_7.1.9580.8513 contain four vulnerabilities affecting critical manufacturing infrastructure worldwide. Attackers could decrypt sensitive data with read access to project files, brute-force weak password hashes to escalate privileges, perform unauthenticated information disclosure, or execute arbitrary JavaScript through social engineering. AVEVA released Security Update 2025 SP1 P2 as a mandatory one-way migration, requiring password resets and stricter access controls for older project files that cannot be upgraded.
Why it matters: Organizations operating AVEVA Pipeline Integrity Monitor in critical manufacturing environments must immediately apply Security Update 2025 SP1 P2 and reset all PIMBoards user passwords; CVE-2026-81821 and CVE-2026-81822 enable local attackers to extract encryption keys and brute-force credentials to gain administrative access.
- Source published
- First seen by Cybersecurity Tracker