Multiple Critical Vulnerabilities Discovered in Panduit IntraVUE Software
Critical security flaws in Panduit IntraVUE software could allow unauthorized users to access industrial control systems, view sensitive data, or bypass network security controls. Organizations using versions 3.2.1a14 and older are urged to update immediately.

English Brief
Critical security flaws in Panduit IntraVUE software could allow unauthorized users to access industrial control systems, view sensitive data, or bypass network security controls. Organizations using versions 3.2.1a14 and older are urged to update immediately.
الموجز العربي
اكتشاف ثغرات أمنية حرجة متعددة في برنامج Panduit IntraVUE
تم اكتشاف ثغرات أمنية حرجة في برنامج Panduit IntraVUE قد تسمح للمستخدمين غير المصرح لهم بالوصول إلى أنظمة التحكم الصناعية، أو الاطلاع على بيانات حساسة، أو تجاوز ضوابط أمن الشبكة. يُحث المستخدمون الذين يستخدمون الإصدارات 3.2.1a14 وما قبلها على التحديث فوراً.
- 1Identify all instances of IntraVUE version <= 3.2.1a14 in the environment.
- 2Download patch version 3.2.1a16 or later from the vendor portal.
- 3Schedule maintenance window for patching.
English Advisory
// Intelligence Summary
Multiple vulnerabilities have been identified in Pronetiqs Panduit IntraVUE software (versions 3.2.1a14 and prior), exposing industrial control environments to potential compromise. These flaws include plaintext credential storage, unauthorized proxy capabilities, information exposure, and weak encryption, which could collectively lead to a total loss of confidentiality, integrity, and availability within the OT environment.
التقرير العربي
// ملخص استخباراتي
تم تحديد ثغرات أمنية متعددة في برنامج Pronetiqs Panduit IntraVUE (الإصدارات 3.2.1a14 وما قبلها)، مما يعرض بيئات التحكم الصناعية لخطر الاختراق. تشمل هذه الثغرات تخزين بيانات الاعتماد بنص واضح، وقدرات الوكيل غير المقصودة، وكشف معلومات النظام، وضعف التشفير، مما قد يؤدي مجتمعة إلى فقدان كامل لسرية وسلامة وتوافر بيئة تكنولوجيا التشغيل (OT).
// Technical Context
The identified CVEs include:
- CVE-2026-40430: Plaintext storage of passwords via API.
- CVE-2026-42933: Unintended proxy/intermediary functionality allowing OT segmentation bypass.
- CVE-2026-44955 / CVE-2026-28698: Exposure of sensitive system information including file system shares.
- CVE-2026-50044: Inadequate encryption strength facilitating pass-the-hash attacks.
// السياق الفني
تشمل رموز التعريف الخاصة بالثغرات المكتشفة:
- CVE-2026-40430: تخزين كلمات المرور بنص واضح عبر واجهة برمجة التطبيقات (API).
- CVE-2026-42933: وظيفة وكيل (Proxy) غير مقصودة تسمح بتجاوز تقسيم الشبكة الصناعية.
- CVE-2026-44955 / CVE-2026-28698: كشف معلومات النظام الحساسة بما في ذلك مشاركات ملفات النظام.
- CVE-2026-50044: ضعف قوة التشفير مما يسهل هجمات تمرير التجزئة (Pass-the-Hash).
// Exposure Notes
Affected software is widely deployed in industrial control sectors globally, including critical manufacturing, energy, and water/wastewater management. The vulnerabilities are reachable over the network without requiring physical access, significantly increasing the risk profile for connected OT assets.
// ملاحظات التعرض
يتم استخدام البرنامج المتأثر على نطاق واسع في قطاعات التحكم الصناعية عالمياً، بما في ذلك التصنيع الحيوي، الطاقة، والمياه والصرف الصحي. يمكن الوصول إلى هذه الثغرات عبر الشبكة دون الحاجة إلى وصول مادي، مما يزيد بشكل كبير من مستوى المخاطر لأصول تكنولوجيا التشغيل المتصلة.
// Defensive Priority
Organizations must immediately patch affected deployments to version 3.2.1a16 or later. Until patching is completed, network segmentation should be strictly enforced to limit reachability of the IntraVUE interface, and administrative credentials should be rotated if exposed.
// أولوية الدفاع
يجب على المؤسسات تحديث الأنظمة المتأثرة فوراً إلى الإصدار 3.2.1a16 أو أحدث. حتى اكتمال التحديث، يجب تطبيق تقسيم الشبكة بصرامة للحد من الوصول إلى واجهة IntraVUE، ويجب تغيير بيانات الاعتماد الإدارية إذا كانت قد تعرضت للخطر.
Mitigation Checklist
- 1Identify all instances of IntraVUE version <= 3.2.1a14 in the environment.
- 2Download patch version 3.2.1a16 or later from the vendor portal.
- 3Schedule maintenance window for patching.
- 4Before patching, backup system configurations and databases.
- 5Apply the software update.
- 6Verify version in settings after restart.
- 7Rotate administrative credentials due to potential plaintext exposure.
قائمة إجراءات التخفيف
- 1تحديد جميع حالات الإصدار 3.2.1a14 وما قبلها من برنامج IntraVUE في البيئة.
- 2تنزيل الإصدار التحديثي 3.2.1a16 أو أحدث من بوابة المورد.
- 3جدولة نافذة صيانة لتطبيق التحديث.
- 4قبل التحديث، قم بأخذ نسخة احتياطية من تكوينات النظام وقواعد البيانات.
- 5تطبيق تحديث البرنامج.
- 6التحقق من رقم الإصدار في الإعدادات بعد إعادة التشغيل.
- 7تغيير بيانات الاعتماد الإدارية نظراً لاحتمالية كشف كلمات المرور بنص واضح.
- Source: CISA Alerts
# Remediation Checklist for Panduit IntraVUE:
# 1. Identify all instances of IntraVUE version <= 3.2.1a14 in the environment.
# 2. Download patch version 3.2.1a16 or later from the vendor portal.
# 3. Schedule maintenance window for patching.
# 4. Before patching, backup system configurations and databases.
# 5. Apply the software update.
# 6. Verify version in settings after restart.
# 7. Rotate administrative credentials due to potential plaintext exposure.