CVE-2026-65310
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ANDRITZ | HIPASE-250 | 0 <= 7.20 | affected |
| ANDRITZ | HIPASE-250 | 7.40 | unaffected |
| ANDRITZ | 250 SCALA | 0 <= 7.20 | affected |
| ANDRITZ | 250 SCALA | 7.40 | unaffected |
Weaknesses
- CWE-306: CWE-306 Missing authentication for critical function
- CWE-942: CWE-942 Permissive cross-domain security policy with untrusted domains
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.