Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NDefault status
unaffected
All versions
affected
Default status
unaffected
All versions
affected
Description
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise the device.
Problem types
Product status
All versions
All versions
References
www.cisa.gov/news-events/ics-advisories/icsa-26-106-03
github.com/...p/csaf_files/OT/white/2026/icsa-26-106-03.json