CVE-2026-42933 PUBLISHED

Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs

Assigner: icscert
Reserved: 15.06.2026 Published: 23.07.2026 Updated: 24.07.2026

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor Pronetiqs
Product Panduit Intravue
Versions Default: unaffected
  • affected from 0 to 3.2.1a14 (incl.)

Solutions

Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.  For further questions, please contact Pronetiqs at info@pronetiqs.com.

Credits

  • Phlebas of Lumintel reported this vulnerability to CISA finder

References

Problem Types

  • CWE-441 Unintended Proxy or Intermediary ('Confused Deputy') CWE