Executive brief
ARC Informatique PcVue, a platform used for monitoring industrial and building automation systems, contains a security flaw where the web server fails to set proper security headers. This oversight can leave users vulnerable to web-based attacks such as Cross-Site Scripting (XSS) when interacting with the software's web interfaces. An attacker could potentially exploit this to execute unauthorized scripts in a user's browser, compromising their session or data.
Technical details
A vulnerability exists in ARC Informatique PcVue (specifically affecting WebVue, WebScheduler, TouchVue, SnapVue, and Web services) where the web server does not properly set HTTP security headers. This deficiency is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation), leading to potential Cross-Site Scripting (XSS) attacks. An unauthenticated remote attacker can exploit this by inducing a user to interact with a malicious link or crafted response, allowing the execution of arbitrary script code in the context of the user's browser session. The issue affects versions 16.x prior to 16.3.4, 15.x prior to 15.2.13, and version 12.0.0. Patching to version 16.3.4 or later is recommended.
Affected products
- ARC Informatique PcVue 16.0.0 to 16.3.3, 15.0.0 to 15.2.13, 12.0.0
Timeline
- 2026-02-26: disclosed
- 2026-02-26: advisory