Executive brief
Pronetiqs IntraVUE, a software tool used to monitor and manage industrial control system (ICS) networks, contains a security flaw where user passwords are stored in plain text. An attacker could exploit this to steal login credentials through the application's programming interface (API). This could lead to unauthorized access to sensitive industrial network data and management functions.
Technical details
A plaintext storage of passwords vulnerability (CWE-256) exists in Pronetiqs IntraVUE versions 3.2.1a14 and prior. The vulnerability is accessible via the application's API, where credentials can be exposed in cleartext to unauthorized users. An attacker with network access to the IntraVUE instance can exploit this flaw without authentication or user interaction to obtain valid credentials. This could facilitate further lateral movement or unauthorized configuration changes within the industrial control environment. The vendor has released version 3.2.1a16 to address this issue.
Affected products
- Pronetiqs (Panduit) IntraVUE <= 3.2.1a14
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory: CISA Advisory ICSA-26-204-04 published
- 2026-07-23: patched: Version 3.2.1a16 released