Panduit IntraVUE
Summary
CISA has issued an alert regarding multiple vulnerabilities in Panduit IntraVUE software versions 3.2.1a14 and prior. Successful exploitation could allow an attacker with IT network access to manipulate industrial control devices without requiring physical access or specialized knowledge.
IFF Assessment
The identified vulnerabilities in Panduit IntraVUE allow for unauthorized manipulation of industrial control devices, posing a significant risk to critical infrastructure.
Severity
The CVSS v3.1 score of 10.0 indicates a critical severity. This is attributed to the attack vector being on the network, requiring no privileges or user interaction, and resulting in a complete loss of confidentiality, integrity, and availability, enabling manipulation of critical industrial control devices.
Defender Context
Defenders should prioritize patching or mitigating affected Panduit IntraVUE systems to prevent unauthorized access and manipulation of industrial control devices. This highlights the ongoing risks associated with vulnerabilities in operational technology (OT) environments, where successful exploitation can have severe real-world consequences.