AVEVA Pipeline Integrity Monitor
Summary
Multiple vulnerabilities have been identified in AVEVA Pipeline Integrity Monitor versions prior to 2025_SP1_P1_build_7.1.9580.8513, potentially allowing attackers to disclose information, brute-force hashes, or execute arbitrary code. These vulnerabilities affect critical infrastructure sectors globally, with the United Kingdom as the company's headquarters. The identified issues include use of hard-coded cryptographic keys, broken cryptographic algorithms, missing authorization, and cross-site scripting.
IFF Assessment
The identified vulnerabilities allow attackers to disclose sensitive information, brute-force credentials, or execute arbitrary code, posing a direct threat to system security.
Severity
Defender Context
Defenders should prioritize patching or applying security updates for AVEVA Pipeline Integrity Monitor to mitigate these critical vulnerabilities. Organizations using affected versions should review access controls for project files and consider the risk of password leakage from unmigrated backups. This highlights the ongoing need for vigilance in securing operational technology (OT) systems, especially within critical infrastructure.