Pronetiqs vulnerabilities
5 CVEs tracked
Pronetiqs appears in our reports with a cluster of critical vulnerabilities affecting IntraVUE versions 3.2.1a14 and prior. Key events include a proxy vulnerability that can bypass OT network segmentation (CVE-2026-42933), exposure of sensitive information allowing unauthenticated asset discovery (CVE-2026-44955), and inadequate encryption strength enabling theft of admin credentials via pass-the-hash attacks (CVE-2026-50044). Defenders must also address filesystem exposure (CVE-2026-28698) and plaintext password leakage through the API (CVE-2026-40430) by urgently updating the software and implementing compensating network-level controls.
Azərbaycanca: Pronetiqs bizim hesabatlarda IntraVUE məhsulunun 3.2.1a14 və əvvəlki versiyalarını əhatə edən kritik zəifliklər toplusu ilə görünür. Əsas hadisələr OT şəbəkə seqmentasiyasını keçə bilən proxy zəifliyi (CVE-2026-42933), autentifikasiya olmadan aktiv kəşfinə imkan verən məlumat sızması (CVE-2026-44955) və zəif şifrələmə səbəbindən admin etimadnamələrinin oğurlanması riskidir (CVE-2026-50044). Müdafiəçilər həmçinin fayl sisteminin ifşasına (CVE-2026-28698) və API vasitəsilə açıq mətn parolların sızmasına (CVE-2026-40430) qarşı tədbir görməli, dərhal proqram təminatını yeniləməli və şəbəkə səviyyəsində kompensasiyaedici nəzarətləri tətbiq etməlidir.
This vendor's CVEs5
This hub is built from skopnix's own reporting on Pronetiqs: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.