Executive brief
Pronetiqs IntraVUE, a software tool used to monitor and manage industrial control system (ICS) networks, contains a security weakness in how it encrypts credentials. An attacker with low-level access to the network could exploit this weak encryption to steal administrative passwords. This could allow an unauthorized user to take full control of the monitoring system and potentially manipulate industrial devices.
Technical details
Pronetiqs IntraVUE (versions 3.2.1a14 and prior) suffers from inadequate encryption strength (CWE-326). The vulnerability stems from the use of weak cryptographic hashes for credential storage or transmission. A network-based attacker with low-privileged access can exploit this to recover administrative credentials or perform pass-the-hash attacks. While the attack requires high complexity (AC:H), successful exploitation grants the attacker high confidentiality and integrity impact over the system. Users are advised to upgrade to version 3.2.1a16 or later to remediate the issue.
Affected products
- Pronetiqs (Panduit) IntraVUE <= 3.2.1a14
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory: CISA Advisory ICSA-26-204-04 published