CVE-2026-28698
Pronetiqs · Panduit Intravue
Pronetiqs Panduit Intravue is susceptible to the exposure of sensitive system information to unauthorized actors.
Executive summary
Pronetiqs Panduit Intravue versions 3.2.1a14 and earlier are affected by a security vulnerability that may expose sensitive system information to unauthenticated attackers.
Vulnerability
This vulnerability (CWE-497) involves the exposure of sensitive system information to an unauthorized control sphere. It is an unauthenticated network-based attack that does not require user interaction to succeed.
Business impact
The exposure of sensitive system information can provide attackers with the reconnaissance data necessary to conduct further, more devastating attacks against industrial control environments. With a CVSS score of 8.6, this vulnerability represents a high risk to the confidentiality and security of the affected network infrastructure.
Remediation
Immediate Action: Update the IntraVUE software to version 3.2.1a16 or later as recommended by the vendor.
Proactive Monitoring: Monitor network traffic for unauthorized attempts to query device information or access system configuration endpoints.
Compensating Controls: Isolate the Intravue management interface from public networks or untrusted segments to prevent unauthenticated access.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations using Panduit Intravue must treat this advisory with high urgency. Updating to version 3.2.1a16 is critical to prevent the leakage of sensitive configuration data that could be leveraged to facilitate broader network compromise.