CVE-2026-81821: AVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic key
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AVEVA Pipeline Integrity Monitorto a version that resolves this vulnerability.Fixed in 2025 SP1 P2 - Upgrade
Upgrade
AVEVA Pipeline Integrity Monitorto a version that resolves this vulnerability.Fixed in 2025 SP1 P2 or higher - Configuration
Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.
PIMBoards users password = change - Compensating control
For PIMBoards project files that cannot be migrated (e.g., backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of AVEVA Pipeline Integrity Monitor who can read PIMBoards project files are the relevant exposure group. The issue could allow such a user to decrypt and view sensitive information in those files.
What level of access does an attacker need?
An attacker needs read access to PIMBoards project files. No user interaction is required according to the supplied CVSS vector.