The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
AVEVA recommends the following general defensive measures:
* Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections.
* Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access.
* Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.
AVEVA Pipeline Simulation media delivers AVEVA Pipeline Integrity Monitor:
* All affected versions can be fixed by upgrading to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher:
https://softwaresupportsp.aveva.com/en-US/downloads/products/details/021a26a7-200f-44eb-8cc9-cd57b7e349aa