CVE-2026-40430
Received Received - Intake

Pronetiqs IntraVUE Plaintext Password Storage Vulnerability

Vulnerability report for CVE-2026-40430, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: ICS-CERT

Description

Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pronetiqs intravue to 3.2.1a14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-256 The product stores a password in plaintext within resources such as memory or files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pronetiqs IntraVUE versions 3.2.1a14 and earlier store passwords in plaintext. This means sensitive credentials are saved without encryption, making them easily readable through the API if accessed by unauthorized users.

Detection Guidance

Detecting this vulnerability requires checking for plaintext password storage in Pronetiqs IntraVUE versions 3.2.1a14 or earlier. Inspect API responses and configuration files for exposed credentials. No specific commands are provided in the context.

Impact Analysis

Attackers could exploit this to steal stored credentials, gaining unauthorized access to the system. This may lead to data breaches, system compromise, or further network infiltration depending on the privileges of the exposed accounts.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for protecting sensitive data. Unencrypted storage of credentials could result in non-compliance, leading to legal penalties, fines, or mandatory breach notifications.

Mitigation Strategies

Immediately upgrade to a version of Pronetiqs IntraVUE that is not affected by this vulnerability. Ensure all stored credentials are encrypted and review API access logs for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40430. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart