PatchSiren

Pronetiqs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Pronetiqs CVE published 2026-07-23

CVE-2026-50044

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T23:16:49.170Z and has not been modified since then. Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability. This weakness could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack. The vulnerability has a CVSS score of [truncated]

MEDIUM Pronetiqs CVE published 2026-07-23

CVE-2026-44955

CVE-2026-44955 is a vulnerability in Pronetiqs IntraVUE versions 3.2.1a14 and prior. This vulnerability exposes sensitive system information to unauthorized users, potentially allowing asset discovery. The affected product, IntraVUE, is used for monitoring and managing industrial control systems. The vulnerability has a CVSS score of 6.9 and a severity rating of MEDIUM. Organizations should assess and mit [truncated]

CRITICAL Pronetiqs CVE published 2026-07-23

CVE-2026-42933

A critical vulnerability was found in Pronetiqs IntraVUE versions 3.2.1a14 and prior. This vulnerability is an unintended proxy or intermediary issue that could allow an attacker to bypass OT segmentation using an active proxy. Organizations should review their IntraVUE configurations and implement additional security measures to prevent potential attacks.

HIGH Pronetiqs CVE published 2026-07-23

CVE-2026-40430

CVE-2026-40430 is a HIGH severity vulnerability in Pronetiqs IntraVUE Versions 3.2.1a14 and prior, involving plaintext storage of a password. This vulnerability could expose cleartext credentials through the API, posing a significant risk to organizations using affected versions. The vulnerability's HIGH CVSS score of 8.7 indicates a high likelihood of exploitation and potential impact. Affected product d [truncated]

CRITICAL Pronetiqs CVE published 2026-07-23

CVE-2026-28698

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-28698 was published on 2026-07-23T23:16:48.590Z and has not been modified since then. Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability, which could expose the underlying host/share filesystem. This vulnerability has a [truncated]