Impact
The vulnerability allows an unauthenticated user to perform read operations that are reserved for authorized PIMBoards users, leading to exposure of sensitive project information. This is a missing authorization flaw (CWE‑862) that permits information disclosure without requiring any credentials.
Affected Systems
The affected software is AVEVA Pipeline Integrity Monitor, all versions prior to 2025 SP1 P2. The issue also applies to PIMBoards project files created with older versions. The recommended fix is to upgrade to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or later and migrate legacy project files.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability is of moderate severity and can be exploited remotely without authentication against the PIMBoards API. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers could read confidential pipeline data from project files if network access is not limited, so mitigation is important.
OpenCVE Enrichment