Junglewise Threat Intelligence

CVE-2026-42933: Pronetiqs IntraVUE unintended proxy in OT segmentation bypass

CVE-2026-42933 · Severity: critical · CVSS 10 · Published 2026-07-23

Technologies: Pronetiqs (Panduit) IntraVUE.

Executive brief

Pronetiqs IntraVUE, a network management tool used to monitor industrial control systems, contains a critical security flaw. This vulnerability allows an attacker to use the software as an unauthorized bridge to reach protected industrial equipment. Exploiting this could allow an attacker to bypass network security boundaries and manipulate critical infrastructure devices, potentially leading to operational outages or safety risks.

Technical details

Pronetiqs IntraVUE (versions 3.2.1a14 and prior) is vulnerable to an unintended proxy or intermediary ('Confused Deputy') flaw, tracked as CWE-441. The vulnerability allows a remote, unauthenticated attacker to use the IntraVUE application as a proxy to forward malicious traffic into segmented Operational Technology (OT) networks. By exploiting this, an attacker can bypass network isolation and interact directly with industrial control devices without requiring specialized knowledge or physical access. This issue is resolved in version 3.2.1a16.

Affected products

  • Pronetiqs (Panduit) IntraVUE <= 3.2.1a14

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory: CISA Advisory ICSA-26-204-04 published
  • 2026-07-23: patched: Fix available in version 3.2.1a16

References