CVE-2026-65311

MEDIUM

ANDRITZ HIPASE-250 - Missing Authentication for Logging-Configuration Endpoint

Title source: rule
STIX 2.1

Description

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-284 CWE-306 CWE-532
Status published
Products (4)
ANDRITZ/250 SCALA < 7.20
ANDRITZ/250 SCALA 8.00
ANDRITZ/HIPASE-250 < 7.20
ANDRITZ/HIPASE-250 8.00
Published Jul 31, 2026
Tracked Since Jul 31, 2026