Machine-generated analysis · WAYSCloud LLM
IntraVUE versions up to 3.2.1a14 store passwords in cleartext via the API. The same versions also allow an attacker to act as an active proxy, bypassing OT segmentation.
Context
Panduit IntraVUE, supplied by Pronetiqs, is an industrial control system management platform. The advisory reports that versions 3.2.1a14 and earlier expose cleartext credentials through the API and permit an unintended proxy that can bypass OT segmentation. These products are deployed worldwide across critical manufacturing, energy, IT, and water sectors.
Operator considerations
Check: inventory IntraVUE installations and verify they are not running version 3.2.1a14 or earlier.
Isolate: restrict API access from the corporate IT network until the software is updated.
Patch: apply the vendor-provided update to version 3.2.1a16 or later.
Log: monitor API calls for unusual credential retrieval or proxy activity.
Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.
The following versions of Panduit IntraVUE are affected:
IntraVUE
Read the full advisory on CISA →