Panduit IntraVUE Multiple Vulnerabilities (Plaintext Credentials, Confused Deputy Proxy, Information Exposure, Weak Encryption)
criticalOtherPanduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including a critical confused-deputy proxy flaw (CVSS 10) that allows attackers with IT network access to bypass OT segmentation and manipulate industrial control devices without authentication. Additional flaws expose plaintext credentials via the API, leak host/share filesystem and asset information to unauthenticated users, and use weak encryption enabling pass-the-hash admin credential theft. CISA advises upgrading to version 3.2.1a16 or later; no known public exploitation has been reported to date.
Updated Jul 27, 2026 · CVSS 10