Impact
The vulnerability exists in the cryptographic handling of PIMBoards user credentials within AVEVA Pipeline Integrity Monitor. The system uses a deprecated or weak password hashing algorithm, allowing attackers who can read PIMBoards project files to perform computational brute‑force attacks on the stored hashes. Successful exploitation yields the attacker with app-native passwords and the ability to elevate to an administrator level within the PIMBoards component.
Affected Systems
All versions of AVEVA Pipeline Integrity Monitor that still rely on the original password hashing scheme are vulnerable, including any installations that retain legacy project files. The problem impacts the Pipeline Integrity Monitor product family and any stored PIMBoards project files that have not been migrated to a newer version. The only mitigation currently available is to install the 2025 SP1 P2 security update and, where feasible, migrate legacy project files to the new hashing mechanism.
Risk and Exploitability
The CVSS score of 8.3 highlights that the weakness has a high impact. Although an EPSS score is not provided, the lack of a KEV listing does not negate the severity of the issue. The attack path requires read access to project files and the ability to perform brute-force operations; attackers with such access can generate credentials to reach administrator rights. As long as old hashes remain in use, the vulnerability persists, and the risk remains elevated until the recommended update and migration are applied.
OpenCVE Enrichment