AVEVA Pipeline Integrity Monitor
AVEVA has released a security bulletin (AVEVA-2026-006) addressing several vulnerabilities in its Pipeline Integrity Monitor software. These vulnerabilities could allow an attacker to disclose sensitive information, brute-force hashes, or execute arbitrary code in a browser session. The primary risk stems from vulnerabilities related to password hashing and project file migration. Organizations using affected versions of AVEVA Pipeline Integrity Monitor should immediately apply the security update and implement stricter read access controls for project files, along with requiring password changes for PIMBoards users.
AVEVA has released a security bulletin (AVEVA-2026-006) addressing several vulnerabilities in its Pipeline Integrity Monitor software. These vulnerabilities could allow an attacker to disclose sensitive information, brute-force hashes, or execute arbitrary code in a browser session. The primary risk stems from vulnerabilities related to password hashing and project file migration. Organizations using affected versions of AVEVA Pipeline Integrity Monitor are urged to take immediate action. Specifically, they should apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files. For project files that cannot be migrated (e.g., backups or transient copies), organizations must evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files. Additionally, AVEVA recommends requiring password changes for PIMBoards users. The vulnerabilities are linked to changes in password hashing algorithms and end-user managed encryption keys, making migration a one-way process. CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, and CVE-2026-81824 are the affected CVEs. The bulletin highlights the importance of minimizing network exposure for control system devices and isolating them from business networks. CISA recommends implementing defensive measures such as VPNs, recognizing that VPNs themselves can have vulnerabilities. Adham Khairy Ramadan (0xadham) reported the vulnerabilities to AVEVA through HackerOne. AVEVA reported the vulnerabilities to CISA. The bulletin also emphasizes the need to avoid social engineering attacks and to implement recommended cybersecurity strategies for proactive defense of ICS assets.