PT-2026-64199 · Pronetiqs · Intravue
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pronetiqs IntraVUE versions 3.2.1a14 and earlier
Description
The software uses inadequate encryption strength, which may enable an attacker to steal administrator credentials. This can be achieved through a weak hash or a pass-the-hash attack, where an attacker uses a captured password hash to authenticate to a system without needing the plaintext password.
Recommendations
Update Pronetiqs IntraVUE to a version later than 3.2.1a14.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intravue