Security Digest: June 22, 2026 - 2 Critical Vulnerabilities
Two high-severity cross-site scripting vulnerabilities in Pilz PASvisu and related PMI systems can let attackers inject malicious code, hijack sessions, and in some cases manipulate process data or gain full control of the device. Patch priority is immediate: upgrade affected systems to the fixed release, restrict access to builder/runtime interfaces, and review for suspicious activity now.
· 5 min read
Urgent Security Alert: Pilz PASvisu XSS Flaws Can Lead to Device Takeover and Process Manipulation
Executive Summary
Two high-severity cross-site scripting vulnerabilities in Pilz PASvisu and related PMI systems can let attackers inject malicious code, hijack sessions, and in some cases manipulate process data or gain full control of the device. Patch priority is immediate: upgrade affected systems to the fixed release, restrict access to builder/runtime interfaces, and review for suspicious activity now.
Critical Vulnerabilities
CVE-2023-45796: Stored XSS in PASvisu Runtime and PMI v8xx
- Impact: A remote attacker with low privileges, or in some cases no authentication, can store malicious script content that executes in the runtime interface. This can be used to manipulate process data and affect integrity and availability of industrial operations.
- Affected Systems: Pilz PASvisu before 1.14.1; PMI v8xx up to and including 2.0.33992.
- Immediate Action: Upgrade immediately to the vendor-fixed version. If patching cannot be completed today, isolate the HMI/runtime environment, restrict who can write process data, and disable any unnecessary user input paths.
- Mitigation: Apply the vendor update, purge untrusted stored content, and review runtime logs for unexpected script-like input or changes to process values. If available, enable network segmentation and least-privilege access for operator accounts.
CVE-2023-45795: XSS in PASvisu Builder Allows Full Device Control
- Impact: A local unauthenticated attacker can inject malicious JavaScript into the Builder component and potentially gain full control of the device.
- Affected Systems: Pilz PASvisu before 1.14.1.
- Immediate Action: Remove local access from untrusted users now, limit Builder use to trusted administrators only, and upgrade to the fixed release as soon as possible.
- Mitigation: Patch to
1.14.1or later, enforce workstation hardening, and verify that no unauthorized scripts, plugins, or modified project files are present on Builder systems.
What to Do Now
- Patch first: Prioritize all Pilz PASvisu and PMI v8xx installations and move them to the vendor-fixed versions.
- Reduce exposure: Restrict network and local access to Builder and Runtime interfaces until patching is complete.
- Review accounts and content: Check for suspicious project files, stored inputs, unexpected process-data changes, and recent admin activity.
- Segment critical systems: Keep HMI/SCADA components off open user networks and isolate them from general-purpose endpoints.
Verification steps:
- Confirm installed versions against the affected ranges:
PASvisu < 1.14.1andPMI v8xx <= 2.0.33992. - Validate that Builder access is limited to trusted staff and that local interactive access is locked down.
- Inspect logs for unusual script strings, repeated input anomalies, or unexpected configuration changes.
Monitoring recommendations:
- Watch for unexpected browser pop-ups, redirects, or injected content in operator interfaces.
- Alert on unauthorized changes to process data, project files, or device settings.
- Increase monitoring of endpoints used for engineering or HMI administration until remediation is verified.
Related Resources
- Internal blog post: “Pilz PASvisu and PMI XSS Exposure: Response Checklist” (to be published).
- Internal blog post: “Industrial HMI Hardening After XSS Disclosure” (to be published).
- Official vendor advisories: Pilz security advisory and release notes for PASvisu 1.14.1; PMI v8xx remediation guidance.