Description
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
Published: 2026-09-08
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via weak password hashing
Action: Patch Immediately
AI Analysis

Impact

The vulnerability exists in the cryptographic handling of PIMBoards user credentials within AVEVA Pipeline Integrity Monitor. The system uses a deprecated or weak password hashing algorithm, allowing attackers who can read PIMBoards project files to perform computational brute‑force attacks on the stored hashes. Successful exploitation yields the attacker with app-native passwords and the ability to elevate to an administrator level within the PIMBoards component.

Affected Systems

All versions of AVEVA Pipeline Integrity Monitor that still rely on the original password hashing scheme are vulnerable, including any installations that retain legacy project files. The problem impacts the Pipeline Integrity Monitor product family and any stored PIMBoards project files that have not been migrated to a newer version. The only mitigation currently available is to install the 2025 SP1 P2 security update and, where feasible, migrate legacy project files to the new hashing mechanism.

Risk and Exploitability

The CVSS score of 8.3 highlights that the weakness has a high impact. Although an EPSS score is not provided, the lack of a KEV listing does not negate the severity of the issue. The attack path requires read access to project files and the ability to perform brute-force operations; attackers with such access can generate credentials to reach administrator rights. As long as old hashes remain in use, the vulnerability persists, and the risk remains elevated until the recommended update and migration are applied.

Generated by OpenCVE AI on September 8, 2026 at 18:35 UTC.

Remediation

Vendor Solution

AVEVA Pipeline Simulation media delivers AVEVA Pipeline Integrity Monitor: * All affected versions can be fixed by upgrading to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher: https://softwaresupportsp.aveva.com/en-US/downloads/products/details/021a26a7-200f-44eb-8cc9-cd57b7e349aa


Vendor Workaround

AVEVA recommends the following general defensive measures: * Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections. * Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access. * Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.


OpenCVE Recommended Actions

  • Upgrade AVEVA Pipeline Integrity Monitor to 2025 SP1 P2 or later and migrate all legacy project files to the secure hashing system
  • Limit read access to PIMBoards project files by applying strict ACLs and restricting user privileges to only those who need it
  • Require all PIMBoards users to change their passwords and disable or isolate accounts that cannot be migrated to the new hashing mechanism

Generated by OpenCVE AI on September 8, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:45:00 +0000


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Aveva
Aveva pipeline Integrity Monitor
Vendors & Products Aveva
Aveva pipeline Integrity Monitor

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
Title AVEVA Pipeline Integrity Monitor Use of a Broken or Risky Cryptographic Algorithm
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Aveva Pipeline Integrity Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-11T14:27:30.585Z

Reserved: 2026-08-27T13:26:11.053Z

Link: CVE-2026-81822

cve-icon Vulnrichment

Updated: 2026-09-08T18:28:58.615Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:20:57.577

Modified: 2026-09-11T15:17:05.520

Link: CVE-2026-81822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:34:23Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm