Executive brief
Pronetiqs IntraVUE, a network management tool used to monitor industrial control systems, contains a critical security flaw. This vulnerability allows an attacker to use the software as an unauthorized bridge to reach protected industrial equipment. Exploiting this could allow an attacker to bypass network security boundaries and manipulate critical infrastructure devices, potentially leading to operational outages or safety risks.
Technical details
Pronetiqs IntraVUE (versions 3.2.1a14 and prior) is vulnerable to an unintended proxy or intermediary ('Confused Deputy') flaw, tracked as CWE-441. The vulnerability allows a remote, unauthenticated attacker to use the IntraVUE application as a proxy to forward malicious traffic into segmented Operational Technology (OT) networks. By exploiting this, an attacker can bypass network isolation and interact directly with industrial control devices without requiring specialized knowledge or physical access. This issue is resolved in version 3.2.1a16.
Affected products
- Pronetiqs (Panduit) IntraVUE <= 3.2.1a14
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory: CISA Advisory ICSA-26-204-04 published
- 2026-07-23: patched: Fix available in version 3.2.1a16