← Knowledge Center
Advisory CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824

AVEVA Pipeline Integrity Monitor Flaws Enable Credential Decryption and Brute-Forcing

CISA has published an advisory covering four vulnerabilities (CVE-2026-81821 through CVE-2026-81824) in AVEVA Pipeline Integrity Monitor versions up to 2025_SP1_P1_build_7.1.9580.8513, with a top CVSS v3 score of 8.4. The flaws stem from a hard-coded cryptographic key, use of a broken or risky cryptographic algorithm, missing authorization, and cross-site scripting. Together they could let an attacker disclose sensitive information, brute-force password hashes, or execute arbitrary code in a browser session.

From an identity and access perspective, the cryptographic weaknesses are the notable concern: a hard-coded key means anyone with read access to PIMBoards project files can decrypt protected data, while a weak hashing algorithm makes stored credentials susceptible to offline brute-forcing. The missing authorization flaw further undermines access control within the application.

What to take away: organizations running this OT/critical-manufacturing software should apply AVEVA’s fixes, restrict access to project files, and treat any credentials that may have been stored with the weak algorithm as potentially compromised and rotate them.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.