VYPR
advisoryPublished Jul 23, 2026· Updated Jul 25, 2026· 1 source

Pronetiqs IntraVUE: Critical OT Bypass and Info Exposure Flaws Disclosed Together

Key findings • Three vulnerabilities disclosed for Pronetiqs IntraVUE on July 23, 2026. • Critical vulnerability (CVE-2026-42933) allows bypassing OT segmentation via unintended proxy. • …

Key findings

  • Three vulnerabilities disclosed for Pronetiqs IntraVUE on July 23, 2026.
  • Critical vulnerability (CVE-2026-42933) allows bypassing OT segmentation via unintended proxy.
  • High-severity flaws expose sensitive system information, aiding asset discovery.
  • Affects IntraVUE versions 3.2.1a14 and prior.
  • Exploitation could allow manipulation of industrial control devices.

On July 23, 2026, a batch of three vulnerabilities was disclosed for Pronetiqs IntraVUE, a product used in critical infrastructure sectors including manufacturing, energy, and water. The vulnerabilities, detailed in a CISA ICS Advisory (ICSA-26-204-04), could allow an attacker with IT network access to manipulate industrial control devices without physical access or specialized knowledge.

The disclosed vulnerabilities include two high-severity flaws and one medium-severity flaw, all affecting IntraVUE versions 3.2.1a14 and prior.

One critical vulnerability (CVE-2026-42933, CVSS 10.0) involves an unintended proxy or intermediary, potentially allowing an attacker to bypass Operational Technology (OT) segmentation. This could enable manipulation of industrial control devices.

Another high-severity vulnerability (CVE-2026-28698, CVSS 8.6) is an exposure of sensitive system information, which could expose the underlying host or shared filesystem to an unauthorized control sphere. This, along with a medium-severity vulnerability (CVE-2026-44955, CVSS 5.3) also related to information exposure, could facilitate asset discovery by unauthenticated users.

Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling. The affected versions are IntraVUE versions 3.2.1a14 and prior. The CISA advisory notes that these vulnerabilities could lead to plaintext storage of a password, unintended proxy usage, exposure of sensitive system information, and inadequate encryption strength.

Users of Pronetiqs IntraVUE are advised to update to a patched version as soon as possible to mitigate the risks associated with these vulnerabilities. The disclosure highlights the importance of securing OT environments and the potential impact of IT network compromises on industrial control systems.

Synthesized by Vypr AI