Four vulnerabilities in AVEVA Pipeline Integrity Monitor enable information disclosure, password hash brute-forcing, unauthorized reads, and XSS; update to 2025 SP1 P2 immediately. AVEVA Pipeline Integrity Monitor versions through 2025 SP1 P1 build 7.1.9580.8513 contain four vulnerabilities spanning hard-coded crypto keys, weak hashing, missing authorization, and stored XSS. Two CVEs score 8.4 HIGH allowing local attackers to decrypt project files and brute-force user passwords for privilege escalation. The remaining two enable unauthenticated information disclosure and browser-session code execution via social engineering.
ICS Vulnerability
4 posts
AVEVA Pipeline Integrity Monitor (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823 +1 more) All-Line Equipment Company Fuel-Boss (CVE-2018-19518, CVE-2019-11043) CISA published an ICS advisory detailing two remote code execution vulnerabilities in All-Line Equipment Company Fuel-Boss V1 products running PHP 7.1.5 or earlier. CVE-2018-19518 exploits argument injection in PHP's imap_open() function to execute arbitrary OS commands. CVE-2019-11043 exploits a buffer overflow in PHP-FPM configurations to achieve remote code execution. Fixes are available for two of four product variants; the remaining two have no fix or no planned fix.
Cyber Centre Daily Advisory Digest — 2026-08-28 (1 advisories) The Canadian Centre for Cyber Security published advisory AV26-856 regarding multiple memory corruption vulnerabilities in National Instruments LabVIEW. The vulnerabilities include an out-of-bounds read via integer conversion and an out-of-bounds write via integer overflow. Affected versions include those prior to 23.0.0, 23.3.10, 24.3.7, 25.3.5, and 26.3.1.
Johnson Controls C-CURE 9000 and Victor application server (Update A) (CVE-2026-21655, CVE-2026-34496, CVE-2026-21653) CISA published an ICS advisory detailing three vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server products. CVE-2026-21655 is a critical .NET deserialization flaw (CVSS 9.6) allowing unauthenticated adjacent-network attackers to achieve remote code execution on port 8999. CVE-2026-21653 is a critical SSRF in Victor Web enabling server-side request forgery against internal services. CVE-2026-34496 is a high-severity privilege issue allowing low-privilege Victor Web users to view unauthorized administrative pages. Vendor upgrades are available for all affected products.