CISA Advisory: Hard-Coded Cryptographic Key Found in AVEVA Pipeline Integrity Monitor

Pipeline corridor protected by fiber sensing cameras and control-center integration

CISA published advisory ICSA-26-253-01 describing four vulnerabilities in AVEVA Pipeline Integrity Monitor, with CVSS scores up to 8.4 (CVE-2026-81821 through CVE-2026-81824). The flaws include a hard-coded cryptographic key, use of a broken or risky cryptographic algorithm, missing authorization checks, and a stored cross-site scripting vulnerability.

According to CISA, successful exploitation could allow an attacker to disclose sensitive project data, brute-force password hashes, or execute arbitrary code in a victim’s browser session. The advisory identifies the Critical Manufacturing sector as affected. AVEVA has released a fix in the 2025 SP1 P2 release.

Why it matters: Pipeline integrity monitoring software is used to track the structural and operational health of oil, gas and other pipeline infrastructure. Vulnerabilities that expose project data or credential material in this class of software are a direct concern for critical-infrastructure operators, even where exploitation requires network access rather than being remotely trivial.

Source: CISA ICS Advisory ICSA-26-253-01, September 10, 2026.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *