Executive brief
Pilz PASvisu and PMI v8xx are visualization and operator interface systems used to monitor and control industrial automation processes. A security vulnerability in these systems allows an attacker to inject malicious scripts that can manipulate live process data. This could lead to unauthorized changes in machinery operations, potentially causing service outages or safety risks in a manufacturing environment.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Runtime component of Pilz PASvisu (versions before 1.14.1) and PMI v8xx (versions up to 2.0.33992). The flaw stems from improper neutralization of input during web page generation (CWE-79). A remote attacker with low privileges can exploit this by injecting malicious JavaScript into the system. Once executed, the script can manipulate process data within the automation application, potentially leading to a loss of integrity or availability of the controlled industrial equipment. A fix is available in PASvisu version 1.14.1 and later.
Affected products
- Pilz PASvisu < 1.14.1
- Pilz PMI v8xx <= 2.0.33992
Timeline
- 2024-01-30: advisory: Initial advisory published by CERT@VDE
- 2026-06-22: disclosed: CVE published to NVD