Security & Threat Intelligence · 23.07.2026, 18:07 UTC
Panduit IntraVUE
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA ICS Advisories · CISA Advisories ↗ |
| Veröffentlicht | 23.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-28698, CVE-2026-40430, CVE-2026-42933, CVE-2026-44955, CVE-2026-50044. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling. The following versions of Panduit IntraVUE are affected:
IntraVUE <=3.2.1a14
CVSS Vendor Equipment Vulnerabilities
v3 10 Pronetiqs Panduit IntraVUE Plaintext Storage of a Password, Unintended Proxy or Intermediary ('Confused Deputy'), Exposure of Sensitive System Information to an Unauthorized Control Sphere, Inadequate Encryption Strength
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Netherlands
Vulnerabilities
Expand All +
CVE-2026-40430
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API. View CVE Details
Affected Products Panduit IntraVUE
Vendor:Pronetiqs Product Version:Pronetiqs IntraVUE: <=3.2.1a14 Product Status:known_affected
Remediations Vendor fixPronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later. MitigationFor further questions, please contact Pronetiqs at info@pronetiqs.com.mailto:info@pronetiqs.com
Relevant CWE: CWE-256 Plaintext Storage of a Password
Metrics
CVSS Version Base Score Base Severity Vector …