CVE-2026-65310
HIGHANDRITZ HIPASE-250 - Missing Authentication and Permissive CORS Policy
Title source: ruleDescription
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-306
CWE-942
Status
published
Products (4)
ANDRITZ/250 SCALA
< 7.20
ANDRITZ/250 SCALA
7.40
ANDRITZ/HIPASE-250
< 7.20
ANDRITZ/HIPASE-250
7.40
Published
Jul 31, 2026
Tracked Since
Jul 31, 2026