CVE-2026-65310

Summary

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.

Affected Software

VendorProductVersion RangeStatus
ANDRITZHIPASE-2500 <= 7.20affected
ANDRITZHIPASE-2507.40unaffected
ANDRITZ250 SCALA0 <= 7.20affected
ANDRITZ250 SCALA7.40unaffected

Weaknesses

  • CWE-306: CWE-306 Missing authentication for critical function
  • CWE-942: CWE-942 Permissive cross-domain security policy with untrusted domains

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References