<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-65309 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-65309/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 16:52:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-65309/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA</title><link>https://feed.craftedsignal.io/briefs/2026-08-andritz-hipase-vulnerabilities/</link><pubDate>Thu, 13 Aug 2026 16:52:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-andritz-hipase-vulnerabilities/</guid><description>ANDRITZ HIPASE-250 and 250 SCALA devices (versions &lt;=7.20) contain multiple high-severity vulnerabilities, including hard-coded credentials, missing authentication on critical functions, and insecure password storage, enabling potential remote exploitation.</description><content:encoded><![CDATA[<p>ANDRITZ HIPASE-250 and 250 SCALA devices (versions 7.20 and earlier) are susceptible to a suite of vulnerabilities that expose critical industrial control system (ICS) infrastructure to unauthorized access and manipulation. These flaws include CVE-2026-65309 (storing passwords in a recoverable format), CVE-2026-65310 (missing authentication for critical configuration endpoints), CVE-2026-65311 (unauthorized modification of logging levels), and CVE-2026-65313 (use of hard-coded credentials for x11vnc).</p>
<p>These issues, impacting the Energy sector globally, stem from insecure design patterns during development and provisioning. An unauthenticated attacker can gain visibility into live process data, recover credentials, or establish remote control over engineering workstations via VNC. These vulnerabilities highlight the risk of exposed ICS management interfaces and the necessity for robust authentication and secure credential management within operational technology (OT) environments. ANDRITZ has released versions V8.00.00 and V8.15.00 to mitigate these risks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows for unauthorized access to process values, potential credential harvesting across the enterprise, and the concealment of malicious activity by disabling system logging. In the context of the Energy sector, these impacts pose significant operational risks, including the potential for unauthorized process manipulation or the compromise of sensitive engineering infrastructure, affecting organizations globally that rely on these ANDRITZ platforms.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all ANDRITZ HIPASE-250 and 250 SCALA instances to version V8.15.00 immediately as specified in the vendor remediation.</li>
<li>Audit network segmentation to ensure management interfaces for HIPASE-250 and 250 SCALA are not reachable from untrusted or public networks to mitigate the risk of unauthenticated access (CVE-2026-65310).</li>
<li>Review all engineering workstations for VNC services and change default passwords immediately to address CVE-2026-65313.</li>
<li>Implement monitoring for unauthorized or anomalous access to configuration endpoints and log-level adjustment endpoints, particularly targeting the specific undocumented interfaces described in CVE-2026-65311.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ics</category><category>energy</category><category>ot</category><category>vulnerability</category><category>cve-2026-65309</category><category>cve-2026-65310</category><category>cve-2026-65311</category><category>cve-2026-65313</category></item></channel></rss>