Executive brief
PcVue is a software platform used for monitoring and controlling industrial systems like power grids, water treatment, and building automation. A security flaw in older versions allows a person with local access to the computer to retrieve the login credentials of built-in users. This could allow an unauthorized individual to gain higher-level access to the control system, potentially disrupting operations or viewing sensitive industrial data.
Technical details
A plaintext storage of passwords vulnerability (CWE-256) exists in ARC Informatique PcVue. The credentials for built-in user accounts are stored insecurely within the 'User' directory of PcVue projects. A local attacker with low privileges can access these files to retrieve credentials, potentially leading to unauthorized administrative access to the SCADA/HMI platform. This vulnerability does not affect Active Directory-integrated accounts. The issue is resolved in version 17.0.0.
Affected products
- ARC Informatique PcVue All versions prior to 17.0.0
Timeline
- 2026-07-07: advisory
- 2026-07-07: disclosed