Executive brief
Pronetiqs IntraVUE, a network management tool used to monitor industrial control systems, contains a vulnerability that allows unauthorized access to sensitive system information. An attacker could exploit this to view files on the underlying host server or shared network drives. This exposure could lead to the theft of configuration data or other sensitive business information, potentially aiding further attacks against the industrial network.
Technical details
Pronetiqs IntraVUE versions 3.2.1a14 and prior are affected by CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). The vulnerability allows a remote, unauthenticated attacker to access sensitive system information, specifically exposing the underlying host or shared filesystem. This occurs because the application does not properly restrict access to system-level data from unauthorized control spheres. Successful exploitation grants the attacker high confidentiality impact by allowing them to read files they should not have access to. The vendor has released version 3.2.1a16 to address this issue.
Affected products
- Pronetiqs IntraVUE <= 3.2.1a14
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory: ICSA-26-204-04 published by CISA
- 2026-07-23: patched: Version 3.2.1a16 released