CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

ANDRITZ HIPASE-250 and 250 SCALA

criticalCVE-2026-65309CVE-2026-65310CVE-2026-65311CVE-2026-65313
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) 250 SCALA <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) CVSS Vendor Equipment Vulnerabilities v3 8.1 ANDRITZ ANDRITZ HIPASE-250 and 250 SCALA Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Austria Vulnerabilities Expand All + CVE-2026-65309 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords. View CVE Details Affected Products ANDRITZ HIPASE-250 and 250 SCALA Vendor: ANDRITZ Product Version: ANDRITZ HIPASE-250: <=7.20, ANDRITZ 250 SCALA: <=7.20 Product Status: known_affected Remediations Vendor fix ANDRITZ has addressed these issues in version V8.00.00 (released 2024-12) and in version V8.15.00 (released 2026-07) and encourages users to keep their systems updated to the latest version (currently HIPASE-250 Version V8.15.00). For more information, users can contact ANDRITZ at the following website: https://www.andritz.com/group-en/contact https://www.andritz.com/group-en/contact Relevant CWE: CWE-257 Storing Passwords in a Recoverable Format Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-65310 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affec

CSIRTS triage

What
The product stores passwords in reversible format and uses hard-coded credentials with missing authentication for critical functions.
Who is affected
ANDRITZ HIPASE-250 and 250 SCALA deployments version 7.20 and earlier worldwide, primarily in energy critical infrastructure.
Urgency
Immediate; critical severity with CVSS 8.1 and hard-coded credentials enable direct unauthorized access to affected devices.
Action
Update to a patched version above 7.20 as soon as possible.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch HIPASE-250 and 250 SCALA

Get an email when a new HIPASE-250 and 250 SCALA advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-13
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-05

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-65309coverage & exploitation statusNVD · CVE.org
CVE-2026-65310coverage & exploitation statusNVD · CVE.org
CVE-2026-65311coverage & exploitation statusNVD · CVE.org
CVE-2026-65313coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for ANDRITZ HIPASE-250 and

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories