CVE-2026-65309
HIGHANDRITZ HIPASE-250 - Storage of Passwords in a Reversible Format
Title source: ruleDescription
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-257
CWE-327
Status
published
Products (4)
ANDRITZ/250 SCALA
< 7.20
ANDRITZ/250 SCALA
7.50
ANDRITZ/HIPASE-250
< 7.20
ANDRITZ/HIPASE-250
7.50
Published
Jul 31, 2026
Tracked Since
Jul 31, 2026