Description
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.
Published: 2026-07-23
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pronetiqs reported that versions 3.2.1a14 and earlier of its Panduit IntraVUE software contain an inadequate encryption strength flaw. The weakness allows an attacker to access administrator credentials by exploiting weak hash algorithms or by performing a pass‑the‑hash operation. With those credentials the attacker could gain unauthorized administrative access to the IntraVUE management interface and potentially manipulate network segmentation settings or other critical security controls.

Affected Systems

Vendors and products affected are Pronetiqs’ Panduit IntraVUE. All installations running version 3.2.1a14 or older are vulnerable. No later versions are impacted, and versions 3.2.1a16 or higher have received a fix.

Risk and Exploitability

The CVSS score of 7.6 indicates a high likelihood of successful exploitation if the vulnerability can be observed. The EPSS score is currently considered rare, and the vulnerability is not listed in CISA KEV. Explicit attack vector details are not supplied in the advisory; it is inferred that the flaw could be exploited by an attacker who has network access to the IntraVUE controller or who obtains a stolen credential hash. Accordingly, the overall risk profile is moderate, contingent on network exposure which is usually confined to trusted management networks.

Generated by OpenCVE AI on August 3, 2026 at 20:49 UTC.

Remediation

Vendor Solution

Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.  For further questions, please contact Pronetiqs at info@pronetiqs.com.


OpenCVE Recommended Actions

  • Apply Pronetiqs recommended update to IntraVUE 3.2.1a16 or newer.
  • Ensure that all administrative credentials use a strong password hashing algorithm, such as bcrypt or Argon2, and re‑hash existing passwords if necessary.
  • Enable multi‑factor authentication for administrative users and restrict administrative access to a whitelisted set of IP addresses.

Generated by OpenCVE AI on August 3, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Pronetiqs
Pronetiqs panduit Intravue
Vendors & Products Pronetiqs
Pronetiqs panduit Intravue

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.
Title Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs
Weaknesses CWE-326
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Pronetiqs Panduit Intravue
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-24T12:38:40.611Z

Reserved: 2026-06-15T17:14:43.844Z

Link: CVE-2026-50044

cve-icon Vulnrichment

Updated: 2026-07-24T12:38:36.470Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T23:16:49.170

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-50044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength