CVSS 10.0CVSS 10.0 · CRITICAL
CVE-2026-42933
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.
View on NVDAnalysis
Pronetiqs IntraVUE presenta una vulnerabilidad de proxy no intencionado que permite a un atacante evadir la segmentación de red en entornos industriales (OT). Con una severidad máxima de 10.0, este fallo facilita el acceso a sistemas críticos aislados mediante el uso del software como intermediario.
Relevant roles
CyberSecurityHardwareBackend
Severity
Score: 10.0(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-441EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.
Published: 7/23/2026, 11:16:48 PM
Last modified: 7/23/2026, 11:16:48 PM