Impact
This vulnerability allows the storage of passwords in plaintext within the Panduit IntraVUE API, enabling an attacker who can access the API to read cleartext credentials. The flaw is categorized as CWE-256, which describes insecure storage of credentials in cleartext. Exposure of these credentials can lead to unauthorized access to systems that rely on those credentials and compromise the confidentiality of the managed environment.
Affected Systems
Pronetiqs Panduit IntraVUE versions 3.2.1a14 and earlier are affected. These versions expose cleartext passwords through the API.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of <1% suggests a low probability of exploitation at present. It is not listed in CISA KEV. The likely attack vector is through the exposed API; an attacker with network access could read stored passwords unless mitigated.
OpenCVE Enrichment