Description
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.
Published: 2026-07-23
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pronetiqs IntraVUE versions 3.2.1a14 and earlier expose sensitive system information to an unauthorized control sphere, allowing unauthenticated users to discover network assets. The vulnerability falls under a CWE‑497 weakness, which signifies insufficient authentication leading to information disclosure. The note in the description explicitly states that the flaw permits asset discovery in the absence of authentication.

Affected Systems

Panduit IntraVUE, deployed by Pronetiqs, is affected for all releases up to and including version 3.2.1a14. The issue is fixed in version 3.2.1a16 or later; users should verify they are running a patched release.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. Based on the description, the attack vector is inferred to involve network access to the IntraVUE control interface, which must be reachable without authentication; the flaw does not provide direct privilege escalation. The EPSS score of less than 1% implies a low probability of widespread exploitation at present, and the vulnerability is not catalogued in CISA KEV. Because asset discovery can inform more targeted attacks, this information disclosure poses a potential future threat to confidentiality and integrity of the system, but immediate denial-of-service or code execution risk is not indicated.

Generated by OpenCVE AI on August 3, 2026 at 20:50 UTC.

Remediation

Vendor Solution

Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.  For further questions, please contact Pronetiqs at info@pronetiqs.com.


OpenCVE Recommended Actions

  • Update IntraVUE to version 3.2.1a16 or later
  • Restrict external access to the control sphere interface via firewalls or network segmentation
  • Monitor system logs for attempts of unauthenticated asset discovery

Generated by OpenCVE AI on August 3, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Pronetiqs
Pronetiqs panduit Intravue
Vendors & Products Pronetiqs
Pronetiqs panduit Intravue

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.
Title Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Pronetiqs Panduit Intravue
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-24T12:39:14.526Z

Reserved: 2026-06-15T17:14:43.840Z

Link: CVE-2026-44955

cve-icon Vulnrichment

Updated: 2026-07-24T12:39:10.931Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T23:16:49.030

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-44955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere