← Back to Feed
ANDRITZ HIPASE-250 and 250 SCALA
CVE-2026-65309CVE-2026-65310CVE-2026-65311CVE-2026-65313
August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL
Multiple vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA (versions <=7.20) include reversible password storage (CVE-2026-65309), missing authentication (CVE-2026-65310), and hardcoded credentials (CVE-2026-65311, 65313). An attacker can exploit these to read device data or gain access to affected workstations. ANDRITZ has released fixes in versions V8.00.00 and V8.15.00; updating is strongly recommended.
Key Takeaways
- Passwords stored and transmitted in reversible format allow recovery from credential store or network.
- Missing authentication for critical functions and hardcoded credentials enable unauthorized access.
- ANDRITZ addressed issues in V8.00.00 and V8.15.00; users should update to latest version.