The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.
Credits
Adham Khairy Ramadan discovered and reported this vulnerability to AVEVA through a private HackerOne bug bounty program.