CVE-2026-42933
Received Received - Intake

Unintended Proxy Vulnerability in Pronetiqs IntraVUE

Vulnerability report for CVE-2026-42933, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: ICS-CERT

Description

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pronetiqs intravue to 3.2.1a14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-441 The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pronetiqs IntraVUE versions 3.2.1a14 and prior contain an unintended proxy or intermediary vulnerability. This flaw allows an attacker to exploit an active proxy to bypass operational technology (OT) network segmentation, potentially enabling unauthorized access to restricted network segments.

Detection Guidance

Detecting this vulnerability requires checking for unintended proxy configurations in Pronetiqs IntraVUE versions 3.2.1a14 and prior. Inspect network traffic for proxy-related anomalies and verify segmentation controls. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow attackers to bypass network segmentation, gaining unauthorized access to critical OT systems. This may lead to operational disruptions, data breaches, or control over industrial processes, depending on the system's configuration and exposure.

Compliance Impact

This vulnerability could potentially allow unauthorized access to operational technology (OT) systems by bypassing network segmentation, which may lead to data breaches or unauthorized data exposure. This could impact compliance with GDPR (if personal data is involved) and HIPAA (if protected health information is compromised) by failing to maintain adequate security controls and data protection measures.

Mitigation Strategies

Update Pronetiqs IntraVUE to the latest version beyond 3.2.1a14 to address the unintended proxy vulnerability. Isolate affected systems from OT segmentation to prevent bypassing security controls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42933. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart