ANDRITZ HIPASE-250 and 250 SCALA
TL;DR
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) 250 SCALA <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) CVSS Vendor Equipment Vulnerabilities
v3 8.1 ANDRITZ ANDRITZ HIPASE-250 and 250 SCALA Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Use of Hard-coded Credentials
Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Austria Vulnerabilities Expand All + CVE-2026-65309 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords. View CVE Details Affected Products ANDRITZ HIPASE-250 and 250 SCALA Vendor: ANDRITZ Product Version: ANDRITZ HIPASE-250: <=7.20, ANDRITZ 250 SCALA: <=7.20 Product Status: known_affected Remediations Vendor fix ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact https://www.andritz.com/group-en/contact Relevant CWE: CWE-257 Storing Passwords in a Recoverable Format Metrics CVSS Version Base Score Base Severity Vector String
3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2026-65310 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default c
What Happened
ANDRITZ HIPASE-250 and 250 SCALA, reported by CISA.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) 250 SCALA <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) CVSS Vendor Equipment Vulnerabilities
v3 8.1 ANDRITZ ANDRITZ HIPASE-250 and 250 SCALA Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Use of Hard-coded Credentials
Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Austria Vulnerabilities Expand All + CVE-2026-65309 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords. View CVE Details Affected Products ANDRITZ HIPASE-250 and 250 SCALA Vendor: ANDRITZ Product Version: ANDRITZ HIPASE-250: <=7.20, ANDRITZ 250 SCALA: <=7.20 Product Status: known_affected Remediations Vendor fix ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact https://www.andritz.com/group-en/contact Relevant CWE: CWE-257 Storing Passwords in a Recoverable Format Metrics CVSS Version Base Score Base Severity Vector String
3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2026-65310 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default c
For the full technical details, see the original report.
Why It Matters for Businesses
This development could affect organizations that rely on the impacted technologies or services. Unpatched systems, misconfigured infrastructure, or lack of monitoring can leave businesses exposed to exploitation, data breaches, and regulatory penalties.
How to Check Your Exposure
Run a free scan on NEL Professional's Cyber Risk Scanner to check whether your domain is affected. The scan covers SSL/TLS, security headers, DNS configuration, email authentication, and more across 16 modules.
Mitigation Steps
- Patch immediately, Apply vendor patches or updates as soon as they are available.
- Review configurations, Check firewall rules, access controls, and security headers.
- Monitor logs, Watch for indicators of compromise (IOCs) related to this threat.
- Update security policies, Ensure incident response plans cover this type of threat.
- Run a security scan, Use automated tools to verify your exposure.
Need Expert Help?
If your organization needs help assessing or remediating this issue, hire a verified cybersecurity specialist through NEL Professionals.
Get up to 100 scans or unlimited lifetime access starting at $15.
View Plans →Comments (0)
No comments yet. Be the first to comment!
