AVEVA Pipeline Integrity Monitor
AVEVA Pipeline Integrity Monitor can let someone with access to project files decrypt and view sensitive information.
- Severity
- HighCVSS 3.1 · 8.4
- Fix
- Not confirmedLast checked today
- Affected versions
- through Versions 2025 SP1 P1 (build 7.1.9580.8513)
- Weakness
- CWE-321
- Exploit likelihood
- 0.10% in 30 daysEPSS, higher than 1% of known flaws
- Affects
- Pipeline Integrity Monitor
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: total
- EU ID
- EUVD-2026-73932ENISA vulnerability database
How it works
- An attacker first needs read access to PIMBoards project files.
- AVEVA Pipeline Integrity Monitor uses a cryptographic key built into the product when protecting information in those files.
- Exploiting this flaw can let that reader decrypt and view sensitive information.
What to do
Check the installed AVEVA Pipeline Integrity Monitor version and build against the affected cutoff in the CISA advisory. Review whether older PIMBoards project files remain, including backups and temporary copies.
Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update or later, then migrate older project files. For files that cannot be migrated, evaluate possible password leakage and restrict read access. Require PIMBoards users to change their passwords.
Technical details
CVE-2026-81821 is a high-severity flaw involving a cryptographic key built into AVEVA Pipeline Integrity Monitor. A user with read access to PIMBoards project files could decrypt protected information. The CVSS 3.1 score is 8.4.
Severity breakdown
- Attack vector Local Needs local access to the machine
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact None No availability impact
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Open in FIRST.org calculatorReferences
- github.com · icsa-26-253-01.json vendor advisory CISA ICS Advisories
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-81821 third party advisory vdb entry
- cvefeed.io · CVE-2026-81821 third party advisory vdb entry
- cwe.mitre.org · 321.html vdb entry
- cwe.mitre.org · 327.html vdb entry
- cwe.mitre.org · 862.html vdb entry
- cwe.mitre.org · 79.html vdb entry
- cveawg.mitre.org · CVE-2026-81821
- aveva.com · SecurityBulletin_AVEVA-2026-006.pdf CISA ICS Advisories
- first.org · 3.1 (3.1) CISA ICS Advisories
- first.org · 4.0 (4.0) CISA ICS Advisories