[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-aveva-patches-four-flaws-in-pipeline-integrity-monitor":10,"sections":45},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":34,"tags":35,"sources":40,"feedback":44,"feedback_at":22,"cost_usd":44,"total_tokens":44},6260,"aveva-patches-four-flaws-in-pipeline-integrity-monitor","AVEVA Patches Four Flaws in Pipeline Integrity Monitor","A hard-coded key exposes secrets, and a weak-hashing bug lets attackers brute-force passwords to reach admin access, among four newly disclosed CVEs.","AVEVA has patched four vulnerabilities in Pipeline Integrity Monitor that could let an attacker read encrypted project data, crack user passwords, or hijack a browser session.\n\nAVEVA's Pipeline Integrity Monitor, used by pipeline operators worldwide, shipped project files protected by a hard-coded encryption key (CVE-2026-81821) and passwords hashed with a broken algorithm (CVE-2026-81822). Anyone with read access to those files could decrypt secrets outright, and separately, could brute-force the weak password hashes, potentially climbing to a PIMBoards administrator account. A missing-authorization bug (CVE-2026-81823) let unauthenticated users pull read-only data, and a cross-site scripting flaw (CVE-2026-81824) let an attacker run JavaScript in a victim's browser if tricked into clicking a malicious link. All four affect versions through 2025 SP1 P1 build 7.1.9580.8513.\n\nPIM software tracks pipeline integrity data for critical manufacturing operators, so the two high-severity flaws (CVSS 8.4 apiece) matter less for their exploit mechanics and more for what they reveal about how the product handled secrets: baking an encryption key into the software and hashing passwords weakly are textbook mistakes, not novel attack techniques. The fix isn't a simple patch either: migrating old project files to the new hashing scheme is one-way, and every PIMBoards user has to reset their password.\n\nCISA's advisory doesn't mention active exploitation, but hard-coded keys and weak hashes are the kind of low-effort findings that show up in industrial software audits far more often than they should.","[\"aveva\",\"vulnerability\",\"ics-security\",\"cisa\"]","2026-09-10T12:00:00.000Z","2026-09-10T16:14:53.440Z","2026-09-10T16:15:05.351Z","published",null,[24,30],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Add the CVE IDs for the third (missing-authorization) and fourth (XSS) vulnerabilities, which are described in detail but left uncredited, and fix the dek\u002Fbody claim that the hard-coded key exposes passwords—per the source, the key exposes general project-file data while password brute-forcing stems from the separate weak-hashing flaw (CVE-2026-81822), so don't conflate the two into a single chained claim the source doesn't state.","resolved",{"id":31,"reviewer":26,"round":32,"reason":33,"status":29},"editor-r2",2,"CVE IDs for the missing-authorization and XSS flaws are now included and the body correctly separates the two flaws, but the dek still lists 'a hard-coded key and weak hashing that could let attackers reach admin access' as a joint outcome — reword the dek so admin-account escalation is attributed only to the weak-hashing flaw (CVE-2026-81822), not to the hard-coded key as well.","security",[36,37,38,39],"aveva","vulnerability","ics-security","cisa",[41],{"name":42,"url":43},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-253-01",0,{"sections":46},[47,52,55,60,65,70,75,79,84,89,94,99,104,109],{"name":48,"slug":49,"count":50,"latest_published_at":51},"AI","ai",3480,"2026-09-11T04:00:00.000Z",{"name":53,"slug":34,"count":54,"latest_published_at":51},"Security",629,{"name":56,"slug":57,"count":58,"latest_published_at":59},"Policy","policy",336,"2026-09-11T00:56:21.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Hardware","hardware",153,"2026-09-09T15:12:32.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":51},"Science","science",98,{"name":80,"slug":81,"count":82,"latest_published_at":83},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"General","general",41,"2026-09-08T01:57:23.000Z",{"name":105,"slug":106,"count":107,"latest_published_at":108},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":110,"slug":111,"count":112,"latest_published_at":113},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]