Impact
Pronetiqs IntraVUE versions 3.2.1a14 and earlier expose sensitive system information to an unauthorized control sphere, allowing unauthenticated users to discover network assets. The vulnerability falls under a CWE‑497 weakness, which signifies insufficient authentication leading to information disclosure. The note in the description explicitly states that the flaw permits asset discovery in the absence of authentication.
Affected Systems
Panduit IntraVUE, deployed by Pronetiqs, is affected for all releases up to and including version 3.2.1a14. The issue is fixed in version 3.2.1a16 or later; users should verify they are running a patched release.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Based on the description, the attack vector is inferred to involve network access to the IntraVUE control interface, which must be reachable without authentication; the flaw does not provide direct privilege escalation. The EPSS score of less than 1% implies a low probability of widespread exploitation at present, and the vulnerability is not catalogued in CISA KEV. Because asset discovery can inform more targeted attacks, this information disclosure poses a potential future threat to confidentiality and integrity of the system, but immediate denial-of-service or code execution risk is not indicated.
OpenCVE Enrichment