Impact
Pronetiqs reported that versions 3.2.1a14 and earlier of its Panduit IntraVUE software contain an inadequate encryption strength flaw. The weakness allows an attacker to access administrator credentials by exploiting weak hash algorithms or by performing a pass‑the‑hash operation. With those credentials the attacker could gain unauthorized administrative access to the IntraVUE management interface and potentially manipulate network segmentation settings or other critical security controls.
Affected Systems
Vendors and products affected are Pronetiqs’ Panduit IntraVUE. All installations running version 3.2.1a14 or older are vulnerable. No later versions are impacted, and versions 3.2.1a16 or higher have received a fix.
Risk and Exploitability
The CVSS score of 7.6 indicates a high likelihood of successful exploitation if the vulnerability can be observed. The EPSS score is currently considered rare, and the vulnerability is not listed in CISA KEV. Explicit attack vector details are not supplied in the advisory; it is inferred that the flaw could be exploited by an attacker who has network access to the IntraVUE controller or who obtains a stolen credential hash. Accordingly, the overall risk profile is moderate, contingent on network exposure which is usually confined to trusted management networks.
OpenCVE Enrichment