IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Panduit IntraVUE

CRITICAL
CVSS 10.0
Date 2026-07-23T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.

// Vulnerabilities (5)

CVE ID CVSS Score Severity Description
CVE-2026-28698 8.6 high
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.
CVE-2026-50044 6.8 medium
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.
CVE-2026-40430 7.5 high
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.
CVE-2026-44955 5.3 medium
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.
CVE-2026-42933 10.0 critical
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

// Remediations (2)

Patch: Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 o
Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.
Mitigation: For further questions, please contact Pronetiqs at [email protected].
For further questions, please contact Pronetiqs at [email protected].

// References