← Back to Feed

ANDRITZ HIPASE-250 and 250 SCALA

CVE-2026-65309CVE-2026-65310CVE-2026-65311CVE-2026-65313

August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL

Multiple vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA (versions <=7.20) include reversible password storage (CVE-2026-65309), missing authentication (CVE-2026-65310), and hardcoded credentials (CVE-2026-65311, 65313). An attacker can exploit these to read device data or gain access to affected workstations. ANDRITZ has released fixes in versions V8.00.00 and V8.15.00; updating is strongly recommended.

Key Takeaways

  • Passwords stored and transmitted in reversible format allow recovery from credential store or network.
  • Missing authentication for critical functions and hardcoded credentials enable unauthorized access.
  • ANDRITZ addressed issues in V8.00.00 and V8.15.00; users should update to latest version.
☕ Buy a Coffee