{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81821","assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","state":"PUBLISHED","assignerShortName":"icscert","dateReserved":"2026-08-27T13:26:10.065Z","datePublished":"2026-09-08T17:42:30.604Z","dateUpdated":"2026-09-11T14:25:51.333Z"},"containers":{"cna":{"providerMetadata":{"orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert","dateUpdated":"2026-09-11T14:25:51.333Z"},"title":"AVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic key","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-321","description":"CWE-321 Use of hard-coded cryptographic key","type":"CWE"}]}],"affected":[{"vendor":"AVEVA","product":"Pipeline Integrity Monitor","versions":[{"status":"affected","version":"0","lessThanOrEqual":"Versions 2025 SP1 P1 (build 7.1.9580.8513)","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.","supportingMedia":[{"type":"text/html","base64":false,"value":"The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information."}]}],"references":[{"url":"https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-253-01.json"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","subIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":8.3,"vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseSeverity":"HIGH","baseScore":8.4,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}}],"workarounds":[{"lang":"en","value":"AVEVA recommends the following general defensive measures:\n  *  Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections.\n  *  Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access.\n  *  Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.","supportingMedia":[{"type":"text/html","base64":false,"value":"AVEVA recommends the following general defensive measures:<br><ul><li><b>Restrict Network Access</b>: Implement host-based and/or network firewall controls on all nodes&nbsp;hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish&nbsp;connections.</li><li><b>Apply strong Access Control Lists</b> to all folders storing project files to ensure only trusted users&nbsp;have read-access.</li><li><b>Maintain a trusted chain-of-custody on project files</b> during creation, modification, distribution,&nbsp;backups, and use.</li></ul>"}]}],"solutions":[{"lang":"en","value":"AVEVA Pipeline Simulation media delivers AVEVA Pipeline Integrity Monitor:\n  *  All affected versions can be fixed by upgrading to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher:\n\n\n https://softwaresupportsp.aveva.com/en-US/downloads/products/details/021a26a7-200f-44eb-8cc9-cd57b7e349aa","supportingMedia":[{"type":"text/html","base64":false,"value":"AVEVA Pipeline Simulation media delivers AVEVA Pipeline Integrity Monitor:<br><ul><li>All affected versions can be fixed by upgrading to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher:</li></ul><a href=\"https://softwaresupportsp.aveva.com/en-US/downloads/products/details/021a26a7-200f-44eb-8cc9-cd57b7e349aa\">https://softwaresupportsp.aveva.com/en-US/downloads/products/details/021a26a7-200f-44eb-8cc9-cd57b7e349aa</a>"}]},{"lang":"en","value":"AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:\n  *  Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.\n  *  For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.\n  *  Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.\n\n\nImportant: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.","supportingMedia":[{"type":"text/html","base64":false,"value":"AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:<br><ul><li>Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project&nbsp;files.</li><li>For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of&nbsp;potential password leakage from these files and implement stricter read access controls to&nbsp;protect these unsafe files.</li><li>Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.</li></ul>Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys."}]}],"credits":[{"lang":"en","value":"Self-discovered and self-reported in accordance with AVEVA’s Ethical Disclosure Policy to inform administrators of potential risks, so that they can take actions to minimize the effects of the vulnerabilities.","type":"finder"}],"source":{"advisory":"AVEVA-2026-006","discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.5"},"datePublic":"2026-09-08T16:58:00.000Z"},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-08T18:29:18.797656Z","id":"CVE-2026-81821","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-08T18:33:51.450Z"}}]}}