CVE-2026-65313

Summary

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

Affected Software

VendorProductVersion RangeStatus
ANDRITZHIPASE-2500 <= 7.20affected
ANDRITZHIPASE-2508.15unaffected
ANDRITZ250 SCALA0 <= 7.20affected
ANDRITZ250 SCALA8.15unaffected

Weaknesses

  • CWE-798: CWE-798
  • CWE-1392: CWE-1392 Use of default credentials

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References