By vendor

Arcinfo vulnerabilities

Known CVEs affecting Arcinfo products, prioritized by severity, with SEC.co remediation and detection guidance.

2 published vulnerabilities

  • CVE-2026-14867MEDIUM 5.5

    PcVue projects store built-in user credentials in an insecure manner within the User directory. A local attacker with limited system access can retrieve these credentials without elevated privileges. Active Directory-integrated accounts are unaffected. The vulnerability exists in all versions before 17.0.0.

  • CVE-2026-14868MEDIUM 5.5

    PcVue, a SCADA/industrial automation platform by ArcInfo, uses weak encryption to protect user account configuration data stored locally in project files. An attacker with local access to a system running PcVue can exploit this weakness to decrypt and modify account settings, potentially escalating their privileges within the application. All versions before 17.0.0 are affected. This is a local-only risk that requires an existing account on the machine, but the consequences—unauthorized administrative access to an industrial control interface—are serious.