HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Plaintext Password Storage Vulnerability (CVE‑2026‑40430) in Panduit IntraVUE Industrial Control Software

Panduit IntraVUE versions ≤ 3.2.1a14 store admin passwords in cleartext and expose them via the API (CVE‑2026‑40430, CVSS 10). The flaw threatens SOC 2 compliance because it breaches encryption and access‑control requirements, making continuous‑control evidence essential.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Critical Plaintext Password Storage Vulnerability (CVE‑2026‑40430) in Panduit IntraVUE Industrial Control Software

What It Is — Panduit IntraVUE (pronetiqs.com) versions ≤ 3.2.1a14 store administrator passwords in cleartext and expose them via the product’s API. The flaw also allows an attacker to view sensitive system information and act as a “confused deputy” within the control sphere.

Exploitability — CVSS v3.10 (Critical). No special tools or insider knowledge are required; an adversary who can reach the IT network can retrieve clear‑text credentials and manipulate PLCs or other control devices.

Affected Products — Panduit IntraVUE (Pronetiqs) ≤ 3.2.1a14.

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: Plain‑text credential storage violates SOC 2 CC6.1 (Encryption) and CC7.1 (Logical Access). Mapping this gap to your control framework demonstrates due diligence.
  • Evidence Collection: Continuous monitoring of credential‑handling controls provides audit‑ready evidence that the weakness has been remediated.
  • Third‑Party Assurance: Many enterprise buyers now require proof—via a Trust Center or similar—that critical infrastructure vendors meet SOC 2 security criteria.

Recommended Actions

  • Upgrade immediately to IntraVUE 3.2.1a16 or later, per Pronetiqs’ advisory.
  • Conduct an inventory of all IntraVUE instances and verify that no clear‑text passwords remain in configuration files or APIs.
  • Map the vulnerability to SOC 2 controls (CC6.1, CC7.1) and capture remediation evidence in your continuous‑compliance platform.
  • Review and harden network segmentation to limit IT‑network access to the control‑system zone.

Source: CISA Advisory – ICSA‑26‑204‑04

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →