Description
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.
Published: 2026-07-23
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows the storage of passwords in plaintext within the Panduit IntraVUE API, enabling an attacker who can access the API to read cleartext credentials. The flaw is categorized as CWE-256, which describes insecure storage of credentials in cleartext. Exposure of these credentials can lead to unauthorized access to systems that rely on those credentials and compromise the confidentiality of the managed environment.

Affected Systems

Pronetiqs Panduit IntraVUE versions 3.2.1a14 and earlier are affected. These versions expose cleartext passwords through the API.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of <1% suggests a low probability of exploitation at present. It is not listed in CISA KEV. The likely attack vector is through the exposed API; an attacker with network access could read stored passwords unless mitigated.

Generated by OpenCVE AI on August 3, 2026 at 20:50 UTC.

Remediation

Vendor Solution

Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.  For further questions, please contact Pronetiqs at info@pronetiqs.com.


OpenCVE Recommended Actions

  • Upgrade Panduit IntraVUE to version 3.2.1a16 or later as advised by Pronetiqs.
  • Configure role‑based access controls to restrict API exposure of credential data.
  • Force migration of any existing plaintext passwords to secure, encrypted storage or a dedicated password vault.

Generated by OpenCVE AI on August 3, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Pronetiqs
Pronetiqs panduit Intravue
Vendors & Products Pronetiqs
Pronetiqs panduit Intravue

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.
Title Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Pronetiqs Panduit Intravue
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-24T12:37:33.801Z

Reserved: 2026-06-15T17:14:43.830Z

Link: CVE-2026-40430

cve-icon Vulnrichment

Updated: 2026-07-24T12:37:26.836Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T23:16:48.743

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-40430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-256

    Plaintext Storage of a Password