CVE-2026-81822
8.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Summary
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AVEVA | Pipeline Integrity Monitor | 0 <= Versions 2025 SP1 P1 (build 7.1.9580.8513) | affected |
Weaknesses
- CWE-327: CWE-327: Use of a Broken or Risky Cryptographic Algorithm
Workarounds
AVEVA recommends the following general defensive measures:
- Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections.
- Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access.
- Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.