ics-otregulatorNewsThe Broadside1 min read

Panduit IntraVUE Plaintext Passwords Enable OT Segmentation Bypass

A management tool trusted to see everything on the OT network stores passwords in plaintext and hands attackers a CVSS 10.0 path across the IT/OT boundary.


TL;DR

CISA's advisory covers five vulnerabilities in Panduit IntraVUE versions 3.2.1a14 and earlier. The critical is CVE-2026-42933 (CVSS 10.0): an unauthenticated attacker can hijack an active proxy to bypass OT segmentation. CVE-2026-40430 (7.5) exposes plaintext credentials through the API. CVE-2026-28698 (8.6) exposes the underlying host filesystem. CVE-2026-50044 (6.8) enables pass-the-hash attacks on admin credentials via weak encryption. CVE-2026-44955 (5.3) allows unauthenticated asset discovery. Pronetiqs patches all five in version 3.2.1a16. No known exploitation reported. Researcher Phlebas of Lumintel reported the vulnerabilities to CISA.

Of the five vulnerabilities, CVE-2026-42933 is the one that demands immediate attention from anyone running IntraVUE between IT and OT. CVSS 10.0. The score reflects what happens when a management tool's proxy function gets hijacked by an unauthenticated attacker: the software you installed to see your network becomes the bridge across segmentation boundaries you assumed were intact.

The threat chain is coherent and ugly. CVE-2026-40430 hands the attacker plaintext credentials through the API. No cracking required. CVE-2026-50044 adds pass-the-hash capability for admin accounts when the plaintext route isn't available. CVE-2026-44955 lets the attacker enumerate assets without authentication, building a map of what's worth targeting. CVE-2026-28698 exposes the underlying filesystem. And CVE-2026-42933 ties it all together by converting a compromised IntraVUE instance into a proxy that reaches into OT networks.

This isn't a vulnerability in an edge device or a PLC. It's in the management layer: the software you installed because you needed visibility into the network. The design assumption that management tools are trustworthy is what makes these vulnerabilities dangerous. IntraVUE sits in exactly the spot where IT-to-OT pivots do the most damage.

The fix is straightforward: update to version 3.2.1a16. But the advisory doesn't specify whether older versions will continue receiving patches, and organizations running IntraVUE in critical manufacturing, energy, or water/wastewater should verify the patch applied. They should also reassess any segmentation assumptions that depended on IntraVUE as a trusted intermediary.


Published ·Deep Fathom