CVE-2026-28698

Pronetiqs · Panduit Intravue

Pronetiqs Panduit Intravue is susceptible to the exposure of sensitive system information to unauthorized actors.

Executive summary

Pronetiqs Panduit Intravue versions 3.2.1a14 and earlier are affected by a security vulnerability that may expose sensitive system information to unauthenticated attackers.

Vulnerability

This vulnerability (CWE-497) involves the exposure of sensitive system information to an unauthorized control sphere. It is an unauthenticated network-based attack that does not require user interaction to succeed.

Business impact

The exposure of sensitive system information can provide attackers with the reconnaissance data necessary to conduct further, more devastating attacks against industrial control environments. With a CVSS score of 8.6, this vulnerability represents a high risk to the confidentiality and security of the affected network infrastructure.

Remediation

Immediate Action: Update the IntraVUE software to version 3.2.1a16 or later as recommended by the vendor.

Proactive Monitoring: Monitor network traffic for unauthorized attempts to query device information or access system configuration endpoints.

Compensating Controls: Isolate the Intravue management interface from public networks or untrusted segments to prevent unauthenticated access.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations using Panduit Intravue must treat this advisory with high urgency. Updating to version 3.2.1a16 is critical to prevent the leakage of sensitive configuration data that could be leveraged to facilitate broader network compromise.