# CVE-2026-65309

## Summary

- **CVE ID:** CVE-2026-65309
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-327, CWE-257
- **Published:** Jul 31, 2026
- **Last Modified:** Jul 31, 2026

## Description

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to recover all stored
passwords.

## Affected Products

- ANDRITZ — HIPASE-250 (0)
- ANDRITZ — HIPASE-250 (7.50)
- ANDRITZ — 250 SCALA (0)
- ANDRITZ — 250 SCALA (7.50)

## References

- [CNA](https://www.andritz.com/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._