VYPR

250 SCALA

by ANDRITZ

CVEs (3)

  • CVE-2026-65311Jul 31, 2026
    risk 0.00cvss epss 0.00

    The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service…

  • CVE-2026-65310Jul 31, 2026
    risk 0.00cvss epss 0.00

    ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values…

  • CVE-2026-65309Jul 31, 2026
    risk 0.00cvss epss 0.00

    ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.