CVE-2026-65311
MEDIUMANDRITZ HIPASE-250 - Missing Authentication for Logging-Configuration Endpoint
Title source: ruleDescription
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.
References (1)
Core 1
Core References
Scores
CVSS v3
5.3
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-284
CWE-306
CWE-532
Status
published
Products (4)
ANDRITZ/250 SCALA
< 7.20
ANDRITZ/250 SCALA
8.00
ANDRITZ/HIPASE-250
< 7.20
ANDRITZ/HIPASE-250
8.00
Published
Jul 31, 2026
Tracked Since
Jul 31, 2026