CVE-2026-81821

Summary

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.

Affected Software

VendorProductVersion RangeStatus
AVEVAPipeline Integrity Monitor0 <= Versions 2025 SP1 P1 (build 7.1.9580.8513)affected

Weaknesses

  • CWE-321: CWE-321 Use of hard-coded cryptographic key

Workarounds

AVEVA recommends the following general defensive measures:

  • Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections.
  • Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access.
  • Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References