CVE-2026-44955
Received Received - Intake

Exposure of Sensitive Information in Pronetiqs IntraVUE

Vulnerability report for CVE-2026-44955, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: ICS-CERT

Description

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pronetiqs intravue to 3.2.1a14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-497 The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pronetiqs IntraVUE versions 3.2.1a14 and prior expose sensitive system information to unauthorized users. This allows unauthenticated individuals to discover assets on the system without proper access rights.

Detection Guidance

This vulnerability allows unauthenticated users to discover sensitive system information. Check for network traffic involving Pronetiqs IntraVUE versions 3.2.1a14 or earlier. Use network scanning tools like nmap to identify IntraVUE services running on default ports. Inspect logs for unusual access attempts to IntraVUE interfaces.

Impact Analysis

An attacker could use this vulnerability to map out your network infrastructure, identify critical assets, and plan further attacks. This increases the risk of data breaches, unauthorized access, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face fines, legal penalties, and reputational damage for non-compliance.

Mitigation Strategies

Upgrade to the latest version of Pronetiqs IntraVUE that addresses this issue. If an upgrade is not immediately possible, restrict network access to IntraVUE systems using firewalls or network segmentation. Ensure IntraVUE interfaces are not exposed to untrusted networks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44955. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart