CVE-2026-65309

Summary

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.

Affected Software

VendorProductVersion RangeStatus
ANDRITZHIPASE-2500 <= 7.20affected
ANDRITZHIPASE-2507.50unaffected
ANDRITZ250 SCALA0 <= 7.20affected
ANDRITZ250 SCALA7.50unaffected

Weaknesses

  • CWE-327: CWE-327
  • CWE-257: CWE-257 Storing passwords in a recoverable format

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References