Cyber Risk

Multiple Critical Flaws Identified in AVEVA Pipeline Integrity Monitor

FORTSECURE GLOBAL· 2026-09-11🛰 CISA Cybersecurity Advisories
#Vulnerability#Cyber Risk#ICS#SCADA

Vulnerabilities in AVEVA Pipeline Integrity Monitor expose industrial control environments to arbitrary code execution and data exposure.

Industrial cybersecurity authorities have published an advisory detailing significant security flaws in the AVEVA Pipeline Integrity Monitor. With a high CVSS vulnerability score of 8.4, the flaws pose substantial operational risks to critical energy and pipeline transport operations.

Risks to Critical Infrastructure Environments

The advisory highlights multiple weaknesses, including the use of hard-coded cryptographic keys, reliance on broken or risky cryptographic algorithms, improper input neutralization, and missing authorization checks. When combined, these vulnerabilities allow a malicious actor to expose confidential operational telemetry, brute-force password hashes, and execute arbitrary code within a targeted user's browser session.

Because pipeline monitoring software supervises the physical integrity and status of distribution infrastructure, compromises in this layer could lead to unauthorized parameter modifications or complete visibility loss for plant operators. Threat actors targeting operational technology (OT) often leverage browser exploitation and credential harvesting to escalate privileges across industrial control architectures.

Mitigation and Hardening Guidance

Organizations utilizing AVEVA Pipeline Integrity Monitor should execute prompt risk management practices. First, apply vendor-recommended updates and software mitigations immediately across all engineering workstations and servers. Second, enforce strict network zoning according to the ISA/IEC 62443 standard, ensuring that industrial control systems and pipeline monitors are isolated from external networks and standard corporate IT domains. Third, prohibit operators from accessing general internet browsing sessions on machines running integrity monitoring tools to reduce the risk of cross-session script execution.


แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog