CVE-2026-42933
Pronetiqs · Panduit Intravue
Pronetiqs Panduit Intravue is vulnerable to an unintended proxy or intermediary flaw that allows unauthenticated attackers to bypass OT network segmentation.
Executive summary
A critical unintended proxy vulnerability in Pronetiqs Panduit Intravue allows unauthenticated remote attackers to bypass critical network segmentation controls.
Vulnerability
This vulnerability, classified as CWE-441 (Confused Deputy), enables an attacker to leverage the software as an active proxy, effectively bridging the gap between disparate network zones. The attack vector is network-based and requires no authentication or user interaction.
Business impact
The ability to bypass OT network segmentation poses a severe risk to industrial control systems and operational technology environments. A successful exploit could lead to unauthorized lateral movement, exposure of sensitive process data, and complete compromise of network integrity. Given the maximum CVSS score of 10.0, this vulnerability represents an extreme risk to business continuity and safety.
Remediation
Immediate Action: Update all instances of Pronetiqs Panduit Intravue to version 3.2.1a16 or later to address the proxy vulnerability.
Proactive Monitoring: Review network access logs for anomalous traffic patterns originating from the Intravue server, particularly connections directed toward restricted OT segments.
Compensating Controls: Implement strict firewall egress filtering for the Intravue server to prevent it from acting as an unauthorized bridge between network zones.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability carries a maximum severity rating and requires immediate attention, particularly for organizations operating within industrial or critical infrastructure sectors. Administrators must prioritize updating to version 3.2.1a16 or later to eliminate the proxy capability and restore network segmentation.