Cyber Resilience
← All news
Confirmed

Panduit IntraVUE

CISA warns that Panduit IntraVUE <=3.2.1a14 lets authenticated network attackers manipulate industrial control devices. If you run IntraVUE, update it now.
Sources (1)
What this means for you — CISO:If Panduit IntraVUE is in your OT estate at ≤3.2.1a14, treat this CISA advisory as a patch priority: an IT-network foothold can reach industrial control devices without physical access or specialized tooling. Confirm version, apply the vendor fix, and verify IT/OT segmentation limits east-west reach to those hosts.
What this means for you — Lean IT orgs:Most lean-IT shops do not run Panduit IntraVUE; you can ignore this unless you operate industrial or manufacturing floor systems that use it. If you do, ask the vendor or integrator managing that gear whether you are on ≤3.2.1a14 and when the update lands.
What this means for you — MSP:Inventory manufacturing and industrial clients for Panduit IntraVUE ≤3.2.1a14 and schedule the vendor update. Flag any deployment where the IntraVUE host is reachable from general IT so segmentation can be tightened while the patch rolls out.
What this means for you — Researcher:CISA ICSA-26-204-04 covers Panduit IntraVUE ≤3.2.1a14; exploitation from the IT network can manipulate ICS devices without physical access or advanced tooling. Pull the CSAF/advisory for CVE and CVSS detail and track the vendor fix against exposed instances.