Description
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
Published: 2026-09-08
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure from hard‑coded cryptographic key
Action: Immediate Patch
AI Analysis

Impact

The vulnerability results from a hard‑coded cryptographic key used to protect PIMBoards project files. If exploited, an individual with read access can decrypt those files and view sensitive information, which constitutes a significant confidentiality risk. The weakness is a classic case of key management failure, identified as CWE‑321. The CVSS score of 8.3 classifies it as high severity, indicating that exploitation can have a serious impact on the confidentiality of the data contained in the project files.

Affected Systems

The affected product is AVEVA Pipeline Integrity Monitor, all versions prior to the 2025 SP1 P2 release. Users of earlier releases who hold PIMBoards project files – including project backups and transient copies – are at risk. PIMBoards users who run the software or manage the API are also exposed to potential data leakage through those files.

Risk and Exploitability

The exploit requires read access to the project files, so the attack vector is likely local or remote if file access can be obtained. With that access an attacker can decrypt and read the contents. The EPSS score is not available, but the CVSS score of 8.3 indicates high severity, reflecting a significant potential impact on confidentiality if exploited. The vulnerability is not currently listed in the CISA KEV catalog. No additional privileges are required beyond file readability, making it a low‑barrier threat for anyone who can reach the files.

Generated by OpenCVE AI on September 8, 2026 at 19:04 UTC.

Remediation

Vendor Solution

AVEVA Pipeline Simulation media delivers AVEVA Pipeline Integrity Monitor: * All affected versions can be fixed by upgrading to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher: https://softwaresupportsp.aveva.com/en-US/downloads/products/details/021a26a7-200f-44eb-8cc9-cd57b7e349aa


Vendor Workaround

AVEVA recommends the following general defensive measures: * Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections. * Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access. * Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.


OpenCVE Recommended Actions

  • Apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 security update and migrate all old PIMBoards project files to the new format. This action removes the hard‑coded key from the project data.
  • For project files that cannot be migrated (e.g., backups or transient copies), evaluate the risk of password leakage from these files and enforce stricter read‑access controls to protect them. Apply ACLs so that only trusted users can read the project files. Maintain a trusted chain‑of‑custody during creation, modification, distribution, and backup of project files to reduce exposure.
  • Require all PIMBoards users to change their passwords to new strong passwords, mitigating the risk that existing passwords could be recovered from the stored files. In environments where network access to the PIMBoards API is unnecessary, restrict it by implementing host‑based or network firewall controls so that only trusted client systems can connect.

Generated by OpenCVE AI on September 8, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:45:00 +0000


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Aveva
Aveva pipeline Integrity Monitor
Vendors & Products Aveva
Aveva pipeline Integrity Monitor

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
Title AVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic key
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Aveva Pipeline Integrity Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-11T14:25:51.333Z

Reserved: 2026-08-27T13:26:10.065Z

Link: CVE-2026-81821

cve-icon Vulnrichment

Updated: 2026-09-08T18:29:32.547Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:20:57.420

Modified: 2026-09-11T15:17:05.390

Link: CVE-2026-81821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:34:21Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key