CVE-2026-32650 PUBLISHED

Anviz CrossChex Standard Algorithm Downgrade

Assigner: icscert
Reserved: 14.04.2026 Published: 17.04.2026 Updated: 17.04.2026

Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling unauthorized database access.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor Anviz
Product Anviz CrossChex Standard
Versions Default: unaffected
  • Version All versions is affected

Workarounds

Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information at https://www.anviz.com/contact-us.html.

References

Problem Types

  • CWE-757 CWE