CVE-2026-33569
בינונית 6.5
תיאור (מקור, אנגלית)
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise the device.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-28/7/2026
- CWE
- CWE-319
מוצרים מושפעים
anviz: cx7 firmware; anviz: cx7; anviz: cx2 lite firmware; anviz: cx2 lite
קישורים
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-… Third Party Advisory
- https://www.anviz.com/contact-us.html Product
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03 US Government Resource