As cited
Copy frozen at (site build).
vulnerabilities
Panduit IntraVUE
Pronetiqs released advisories for four critical and high-severity vulnerabilities in Panduit IntraVUE versions 3.2.1a14 and earlier, affecting industrial control device management across critical manufacturing, energy, and water sectors worldwide. The flaws include plaintext password storage, confused deputy proxy bypass, unauthenticated asset discovery, and weak credential encryption that could allow network-based attackers to manipulate industrial devices. Pronetiqs recommends immediate patching to version 3.2.1a16 or later.
Why it matters: Organizations running IntraVUE for industrial control must patch immediately, as these vulnerabilities expose credentials and allow unauthenticated attackers to bypass network segmentation and manipulate OT devices remotely without specialized access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Panduit IntraVUE
Pronetiqs released advisories for four critical and high-severity vulnerabilities in Panduit IntraVUE versions 3.2.1a14 and earlier, affecting industrial control device management across critical manufacturing, energy, and water sectors worldwide. The flaws include plaintext password storage, confused deputy proxy bypass, unauthenticated asset discovery, and weak credential encryption that could allow network-based attackers to manipulate industrial devices. Pronetiqs recommends immediate patching to version 3.2.1a16 or later.
Why it matters: Organizations running IntraVUE for industrial control must patch immediately, as these vulnerabilities expose credentials and allow unauthenticated attackers to bypass network segmentation and manipulate OT devices remotely without specialized access.
- Source published
- First seen by Cybersecurity Tracker