7.7
CVE-2026-32324
- EPSS 0.09%
- Veröffentlicht 17.04.2026 19:22:12
- Zuletzt bearbeitet 04.05.2026 14:31:57
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Anviz CX7 Firmware Use of Hard-coded Cryptographic Key
Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at scale.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Anviz ≫ Cx7 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.005 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ics-cert@hq.dhs.gov | 7.7 | 2.5 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-321 Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
https://www.anviz.com/contact-us.html
https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-106-03.json