CVE-2026-44955 PUBLISHED

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs

Assigner: icscert
Reserved: 15.06.2026 Published: 23.07.2026 Updated: 24.07.2026

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Pronetiqs
Product Panduit Intravue
Versions Default: unaffected
  • affected from 0 to 3.2.1a14 (incl.)

Solutions

Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later.  For further questions, please contact Pronetiqs at info@pronetiqs.com.

Credits

  • Phlebas of Lumintel reported this vulnerability to CISA finder

References

Problem Types

  • CWE-497 Exposure of sensitive system information to an unauthorized control sphere CWE