Impact
The vulnerability results from a hard‑coded cryptographic key used to protect PIMBoards project files. If exploited, an individual with read access can decrypt those files and view sensitive information, which constitutes a significant confidentiality risk. The weakness is a classic case of key management failure, identified as CWE‑321. The CVSS score of 8.3 classifies it as high severity, indicating that exploitation can have a serious impact on the confidentiality of the data contained in the project files.
Affected Systems
The affected product is AVEVA Pipeline Integrity Monitor, all versions prior to the 2025 SP1 P2 release. Users of earlier releases who hold PIMBoards project files – including project backups and transient copies – are at risk. PIMBoards users who run the software or manage the API are also exposed to potential data leakage through those files.
Risk and Exploitability
The exploit requires read access to the project files, so the attack vector is likely local or remote if file access can be obtained. With that access an attacker can decrypt and read the contents. The EPSS score is not available, but the CVSS score of 8.3 indicates high severity, reflecting a significant potential impact on confidentiality if exploited. The vulnerability is not currently listed in the CISA KEV catalog. No additional privileges are required beyond file readability, making it a low‑barrier threat for anyone who can reach the files.
OpenCVE Enrichment