Panduit IntraVUE
Plan PatchCVSS 10ICS-CERT ICSA-26-204-04Jul 23, 2026
Manufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Panduit IntraVUE versions 3.2.1a14 and earlier contain multiple vulnerabilities (CWE-256, CWE-441, CWE-497, CWE-326) that allow attackers on the IT network to manipulate industrial control devices without requiring credentials, insider knowledge, or physical access. Successful exploitation could allow unauthorized modification of device settings and control commands, affecting connected industrial equipment.
What this means
What could happen
An attacker on your IT network could modify settings or control commands sent to industrial devices through IntraVUE without needing credentials or physical access, potentially disrupting production or equipment operation.
Who's at risk
Manufacturing operations and facilities using Panduit IntraVUE to manage industrial control devices, including production lines, machine controllers, and networked plant equipment that rely on this software for remote monitoring or control.
How it could be exploited
An attacker with access to your IT network intercepts or modifies communications between IntraVUE and connected industrial control devices. The vulnerabilities allow command injection or manipulation of device configurations without authentication, letting the attacker alter process parameters, disable safety features, or stop equipment.
Prerequisites
- Network access to IntraVUE or the devices it communicates with
- IntraVUE version 3.2.1a14 or earlier deployed and operational
remotely exploitableno authentication requiredlow complexityhigh CVSS score (10.0)affects industrial control device commands
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
IntraVUE≤ 3.2.1a14Fix available
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate IntraVUE to version 3.2.1a16 or later
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/82ebd389-be6a-405e-96de-d475b2a20923Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.