VYPR
advisoryPublished Jul 23, 2026· 1 source

Multiple Vulnerabilities in Panduit IntraVUE Threaten Industrial Control Systems

CISA has issued an advisory detailing several critical vulnerabilities in Pronetiqs Panduit IntraVUE software, versions 3.2.1a14 and prior, which could allow attackers to manipulate industrial control devices.

CISA has released an advisory highlighting a series of significant vulnerabilities affecting Pronetiqs Panduit IntraVUE software, specifically versions 3.2.1a14 and earlier. These flaws, if exploited, could grant an attacker the ability to manipulate critical industrial control devices without requiring physical access, specialized insider knowledge, or advanced technical tools. The affected software is deployed globally across various critical infrastructure sectors, including critical manufacturing, energy, information technology, and water and wastewater.

The vulnerabilities identified include CVE-2026-40430, a plaintext storage of a password issue that exposes cleartext credentials via the API. This could allow an attacker to gain unauthorized access by simply retrieving stored credentials. Another critical flaw, CVE-2026-42933, involves unintended proxy usage, potentially enabling an attacker to bypass operational technology (OT) segmentation by leveraging an active proxy. This bypass could open pathways into previously isolated industrial networks.

Further compounding the risk, CVE-2026-44955 and CVE-2026-28698 expose sensitive system information to an unauthorized control sphere. These vulnerabilities could allow unauthenticated users to perform asset discovery or gain access to the underlying host and share file systems, providing attackers with crucial reconnaissance data for future attacks. The severity of these information exposure flaws ranges from medium to high, depending on the specific context of exploitation.

Adding to the list of critical issues is CVE-2026-50044, which points to inadequate encryption strength. This vulnerability could enable an attacker to steal administrative credentials through weak hashing mechanisms or by employing pass-the-hash techniques. The combination of these weaknesses creates a potent attack surface, allowing for credential theft and subsequent unauthorized access to sensitive systems.

Successful exploitation of these vulnerabilities could lead to severe consequences, including unauthorized control of industrial processes, disruption of critical services, and potential physical damage. The CVSS scores for these vulnerabilities range from medium to critical, with CVE-2026-42933 scoring a perfect 10.0 in CVSS v3.1 and v4.0, indicating a critical level of risk.

Pronetiqs, the vendor behind IntraVUE, has released a fix and advises all users to update to the latest version of the software, which is version 3.2.1a16 or later. For organizations unable to immediately update, CISA recommends minimizing network exposure for all control system devices and systems, ensuring they are not accessible from the internet. Isolating control system networks behind firewalls and using secure remote access methods like VPNs are also crucial mitigation strategies.

The advisory was reported to CISA by Phlebas of Lumintel. The widespread deployment of Panduit IntraVUE across critical infrastructure highlights the importance of timely patching and robust security practices to protect industrial control systems from sophisticated cyber threats.

Synthesized by Vypr AI