Executive brief
Pronetiqs IntraVUE, a network management tool used to monitor industrial control systems, contains a security flaw that exposes sensitive system information. An unauthenticated attacker could exploit this to discover internal assets and network details without needing any special access or credentials. This information could be used to plan further attacks against critical infrastructure environments.
Technical details
Pronetiqs IntraVUE versions 3.2.1a14 and prior are vulnerable to CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). The vulnerability allows a remote, unauthenticated attacker to access sensitive system data via the network. This exposure specifically facilitates asset discovery, potentially revealing the topology and identity of devices within an industrial control system (ICS) environment. The issue is resolved in version 3.2.1a16.
Affected products
- Pronetiqs (Panduit) IntraVUE <= 3.2.1a14
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory: ICSA-26-204-04 published by CISA