VYPR
advisoryPublished Aug 13, 2026· 1 source

Multiple Vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA Expose Sensitive Data and System Access

CISA has alerted users to several critical vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA industrial control systems, potentially allowing attackers to read sensitive data and gain unauthorized access.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding multiple vulnerabilities affecting ANDRITZ HIPASE-250 and 250 SCALA systems, specifically versions prior to 7.20. These vulnerabilities, identified under CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, and CVE-2026-65313, pose significant risks to industrial control environments, potentially enabling attackers to read sensitive data or gain unauthorized access to workstations.

One of the primary concerns is CVE-2026-65309, which stems from the way ANDRITZ HIPASE-250 and 250 SCALA systems store and transmit user passwords. Instead of employing secure one-way hashing mechanisms, these versions store passwords in a reversible format. This flaw means that any attacker capable of accessing the credential store or intercepting network traffic could easily recover all stored passwords, leading to widespread account compromise.

Further exacerbating the security posture, CVE-2026-65310 allows unauthenticated attackers with network access to read live process values and server configurations. This is due to the system's data and configuration endpoints being exposed without any authentication and featuring permissive Cross-Origin Resource Sharing (CORS) policies. The lack of authentication on critical endpoints creates an open door for unauthorized information disclosure.

Adding to the severity, CVE-2026-65311 involves an undocumented HTTP server endpoint that allows for the suppression of audit logs without requiring any authentication. An attacker exploiting this vulnerability could disable logging mechanisms, thereby concealing their malicious activities and making forensic analysis significantly more difficult. This could be used to mask other ongoing intrusions or unauthorized system modifications.

Another critical vulnerability, CVE-2026-65313, affects the installation process for HIPASE-250 engineering workstations. A provisioning script used during installation sets a fixed, hard-coded password for the x11vnc service. Since this password is the same across all provisioned workstations, an attacker with adjacent network access who knows this default password can gain VNC access to these systems, enabling further exploitation.

The affected products include ANDRITZ HIPASE-250 and 250 SCALA, with versions up to and including 7.20 being vulnerable. These systems are deployed globally across critical infrastructure sectors, including energy. The potential impact ranges from data exfiltration and system access to the disruption of industrial operations.

ANDRITZ has released patches to address these vulnerabilities. Versions V8.00.00 (released December 2024) and V8.15.00 (released July 2026) contain the necessary fixes. The company strongly advises users to update their systems to the latest version, currently HIPASE-250 Version V8.15.00, to mitigate these risks. Users seeking further assistance can contact ANDRITZ through their official website.

CISA recommends that organizations minimize network exposure for all control system devices and implement rigorous access control measures. Regularly updating software and applying vendor-provided patches are crucial steps in defending against these types of vulnerabilities. The agency also advises users to consult the CISA ICS Advisories page for more information on industrial control system security.

Synthesized by Vypr AI