ANDRITZ HIPASE-250 and 250 SCALA
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) 250 SCALA <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) CVSS Vendor Equipment Vulnerabilities v3 8.1 ANDRITZ ANDRITZ HIPASE-250 and 250 SCALA Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Austria Vulnerabilities Expand All + CVE-2026-65309 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords. View CVE Details Affected Products ANDRITZ HIPASE-250 and 250 SCALA Vendor: ANDRITZ Product Version: ANDRITZ HIPASE-250: <=7.20, ANDRITZ 250 SCALA: <=7.20 Product Status: known_affected Remediations Vendor fix ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact https://www.andritz.com/group-en/contact Relevant CWE: CWE-257 Storing Passwords in a Recoverable Format Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-65310 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affec
CSIRTS triage
- What
- The product stores passwords in reversible format and uses hard-coded credentials with missing authentication for critical functions.
- Who is affected
- ANDRITZ HIPASE-250 and 250 SCALA deployments version 7.20 and earlier worldwide, primarily in energy critical infrastructure.
- Urgency
- Immediate; critical severity with CVSS 8.1 and hard-coded credentials enable direct unauthorized access to affected devices.
- Action
- Update to a patched version above 7.20 as soon as possible.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch HIPASE-250 and 250 SCALA
Get an email when a new HIPASE-250 and 250 SCALA advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-05
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-653090.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653100.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653110.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-653130.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-65309 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65310 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65311 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65313 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-65313: A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering worksta…nvd
- mediumCVE-2026-65311: The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions expo…nvd
- highCVE-2026-65310: ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, ex…nvd
- highCVE-2026-65309: ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwor…nvd
Recent advisories for ANDRITZ HIPASE-250 and
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-65311: The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions expo…nvd · 2026-07-31
- highCVE-2026-65310: ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, ex…nvd · 2026-07-31
- highCVE-2026-65309: ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwor…nvd · 2026-07-31
More from CISA Cybersecurity Advisories
- criticalJohnson Controls Metasys2026-08-13
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalJohnson Controls Inc. Airwall2026-08-13