CVE-2026-65310
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.32%
- CWE
- CWE-306, CWE-942
- Published
- 2026-07-31
- Last modified
- 2026-07-31
Affected products
- ANDRITZ HIPASE-250
- ANDRITZ HIPASE-250
- ANDRITZ 250 SCALA
- ANDRITZ 250 SCALA
Weakness type
Related vulnerabilities
- CVE-2026-88062 — OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
- CVE-2026-9336 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
- CVE-2026-88018 — rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
- CVE-2026-88285 — GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service
- CVE-2026-49362 — Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation
- CVE-2026-49363 — Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription
- CVE-2026-49364 — Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
- CVE-2026-57967 — Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment