Executive brief
PcVue is a monitoring and control platform used in industrial environments like power plants and smart buildings. A security weakness in how the software encrypts user account information allows a local user to bypass security controls. An attacker with basic access to the system could modify account configurations to gain full administrative privileges, potentially allowing them to disrupt operations or access sensitive industrial data.
Technical details
PcVue projects utilize a built-in user directory to store account configurations. Due to the use of an inadequate encryption strength (CWE-326) for protecting these configurations, the security of the user directory is compromised. A local attacker with low privileges can access and alter the stored configuration files. By manipulating these files, the attacker can escalate their privileges to an administrative level within the PcVue application. This vulnerability affects all versions of PcVue prior to 17.0.0; users are advised to upgrade to version 17.0.0 or later to remediate the issue.
Affected products
- ARC Informatique (arcinfo) PcVue All versions prior to 17.0.0
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory