Panduit IntraVUE
Pronetiqs has identified and reported several vulnerabilities in Panduit IntraVUE software versions 3.2.1a14 and earlier, posing significant risks to industrial control systems. These vulnerabilities include plaintext storage of passwords, an unintended proxy vulnerability allowing bypass of OT segmentation, exposure of sensitive system information, and inadequate encryption strength. Users are advised to immediately update to version 3.2.1a16 or later to mitigate these risks. CISA recommends implementing defensive measures to minimize exploitation.
Pronetiqs has identified and reported multiple vulnerabilities within the Panduit IntraVUE software. Specifically, versions 3.2.1a14 and prior are affected by several security flaws. The most critical issue is a plaintext storage of a password vulnerability, which could expose cleartext credentials to an attacker with network access. Furthermore, the software contains an unintended proxy or intermediary vulnerability, allowing an attacker to bypass existing Operational Technology (OT) segmentation and gain unauthorized access to control systems. Another vulnerability exposes sensitive system information to an unauthorized control sphere, and a weak encryption strength allows for potential credential theft via pass-the-hash attacks. CISA recommends that all users of Panduit IntraVUE immediately update to version 3.2.1a16 or later to address these security concerns. The vulnerabilities could allow an attacker to manipulate industrial control devices without requiring physical access or specialized knowledge. Pronetiqs reported these vulnerabilities to CISA. CISA recommends organizations take defensive measures, including minimizing network exposure for control system devices, isolating them from business networks, and utilizing secure remote access methods like VPNs (while recognizing VPN vulnerabilities). Organizations are encouraged to perform impact analysis and risk assessments and to implement recommended cybersecurity strategies for proactive defense of ICS assets. CISA also advises users to be vigilant against social engineering attacks and to report any suspected malicious activity.