Skip to main content
CISA — industrial system·AT·

ANDRITZ HIPASE-250 and 250 SCALA

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) 250 SCALA <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313) CVSS Vendor Equipment Vulnerabilities v3 8.1 ANDRITZ ANDRITZ HIPASE-250 and 250 SCALA Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Austria Vulnerabilities Expand All + CVE-2026-65309 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords. View CVE Details Affected Products ANDRITZ HIPASE-250 and 250 SCALA Vendor: ANDRITZ Product Version: ANDRITZ HIPASE-250: <=7.20, ANDRITZ 250 SCALA: <

More from CISA — industrial system

The rest of this wire is for subscribers

Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.

7 days, no card required.

Read releases like this the second they cross the wire.

1,200+live on PPN World right now. Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.

Start the free trial →

Your announcement next? Distribute your press release to the global wires with PPN Source — and track its pickup live here.

PPN Source →
Shared via PPN World — real-time press release intelligence.