criticalOther

Panduit IntraVUE Multiple Vulnerabilities (Plaintext Credentials, Confused Deputy Proxy, Information Exposure, Weak Encryption)

First seen Jul 27, 2026 · Updated Jul 27, 2026 · CVSS 10

ICSOTindustrial-control-systemsCISAplaintext-passwordconfused-deputypass-the-hashweak-encryptioncritical-infrastructure

Panduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including a critical confused-deputy proxy flaw (CVSS 10) that allows attackers with IT network access to bypass OT segmentation and manipulate industrial control devices without authentication. Additional flaws expose plaintext credentials via the API, leak host/share filesystem and asset information to unauthenticated users, and use weak encryption enabling pass-the-hash admin credential theft. CISA advises upgrading to version 3.2.1a16 or later; no known public exploitation has been reported to date.

Technical Analysis

The advisory discloses five CVEs affecting Pronetiqs' Panduit IntraVUE ICS visibility software: CVE-2026-40430 (CWE-256, plaintext password storage exposing credentials via API, CVSS3.1 7.5), CVE-2026-42933 (CWE-441, confused deputy proxy allowing OT segmentation bypass, CVSS3.1 10.0/CVSS4.0 10.0), CVE-2026-44955 (CWE-497, unauthenticated asset discovery via sensitive system information exposure, CVSS3.1 5.3), CVE-2026-50044 (CWE-326, inadequate encryption strength enabling pass-the-hash admin credential theft, CVSS3.1 6.8), and CVE-2026-28698 (CWE-497, exposure of underlying host/share filesystem, CVSS3.1 8.6/CVSS4.0 9.2). Collectively these allow a network-adjacent attacker without prior authentication or specialized tooling to pivot from IT to OT networks, harvest credentials, and manipulate industrial control devices, posing severe risk to Critical Manufacturing, Energy, IT, and Water/Wastewater sectors. Organizations running AI agents or automation frameworks that orchestrate ICS/OT monitoring or that integrate with IntraVUE-connected networks for asset visibility could have API keys, service credentials, or agent-tool secrets exposed via the plaintext storage and filesystem disclosure flaws, and the confused-deputy proxy could be abused as a pivot point to reach agent-controlled infrastructure sitting on the same segmented network.

Affected Systems

Panduit IntraVUE (developed by Pronetiqs), all versions <=3.2.1a14; deployed worldwide across Critical Manufacturing, Energy, Information Technology, and Water and Wastewater sectors.

Indicators of Compromise

  • No known IOCs published; no public exploitation reported to CISA at this time.

Remediation Steps

  1. 1

    Upgrade IntraVUE

    Update to Panduit IntraVUE version 3.2.1a16 or later, which addresses all five identified vulnerabilities.

  2. 2

    Network segmentation

    Ensure control system networks and devices are isolated behind firewalls and separated from business/IT networks; do not expose IntraVUE or ICS devices directly to the internet.

  3. 3

    Secure remote access

    Use up-to-date VPNs for any required remote access to ICS environments, and treat VPN endpoints as only as secure as the connected devices.

  4. 4

    Credential rotation

    Rotate any credentials that may have been stored in plaintext or transmitted via weak encryption, including admin and API credentials, following the update.

  5. 5

    Monitor and report

    Monitor for anomalous proxy/traffic behavior indicative of confused-deputy exploitation and report suspected malicious activity to CISA.

  6. 6

    Vendor contact

    Contact Pronetiqs (info@pronetiqs.com) for further guidance on mitigation and patch verification.

CVE / Advisory IDs

CVE-2026-40430CVE-2026-42933CVE-2026-44955CVE-2026-50044CVE-2026-28698

Industries Most Exposed

Critical ManufacturingEnergyInformation TechnologyWater and Wastewater

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.