CVE-2026-32650

Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling unauthorized database access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anviz:crosschex_standard:-:*:*:*:*:*:*:*

History

04 May 2026, 14:38

Type Values Removed Values Added
First Time Anviz
Anviz crosschex Standard
References () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-106-03.json - () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-106-03.json - Third Party Advisory
References () https://www.anviz.com/contact-us.html - () https://www.anviz.com/contact-us.html - Product
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03 - US Government Resource
CPE cpe:2.3:a:anviz:crosschex_standard:-:*:*:*:*:*:*:*

17 Apr 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-17 20:16

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32650

Mitre link : CVE-2026-32650

CVE.ORG link : CVE-2026-32650


JSON object : View

Products Affected

anviz

  • crosschex_standard
CWE
CWE-757

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')