CVE-2026-32650
גבוהה 7.5
תיאור (מקור, אנגלית)
Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling unauthorized database access.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-28/7/2026
- CWE
- CWE-757
מוצרים מושפעים
anviz: crosschex standard
קישורים
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-… Third Party Advisory
- https://www.anviz.com/contact-us.html Product
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03 US Government Resource