Impact
Pronetiqs IntraVUE versions 3.2.1a14 and earlier contain an unintended proxy or intermediary flaw that permits an attacker to use an active proxy. By doing so, the attacker can bypass the intended OT network segmentation enforced by the IntraVUE device. This violation of network boundaries can expose operational technology assets to external actors, potentially allowing unauthorized access, manipulation or disruption of industrial control processes.
Affected Systems
The flaw affects Pronetiqs IntraVUE, specifically versions 3.2.1a14 and earlier. Updated releases 3.2.1a16 and later are free from this issue.
Risk and Exploitability
With a CVSS score of 10, the vulnerability is considered critical. The EPSS score of less than 1% indicates a low probability of exploitation, and it is not listed in CISA's KEV catalog. The likely attack vector is remote, requiring the attacker to connect to the IntraVUE system from outside the OT network. Once the proxy is hijacked, the attacker can route traffic into the OT segment, compromising its security posture.
OpenCVE Enrichment