{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-65311/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-65309"},{"cvss":7.5,"id":"CVE-2026-65310"},{"cvss":5.3,"id":"CVE-2026-65311"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HIPASE-250","250 SCALA"],"_cs_severities":["high"],"_cs_tags":["ics","energy","ot","vulnerability","cve-2026-65309","cve-2026-65310","cve-2026-65311","cve-2026-65313"],"_cs_type":"advisory","_cs_vendors":["ANDRITZ"],"content_html":"\u003cp\u003eANDRITZ HIPASE-250 and 250 SCALA devices (versions 7.20 and earlier) are susceptible to a suite of vulnerabilities that expose critical industrial control system (ICS) infrastructure to unauthorized access and manipulation. These flaws include CVE-2026-65309 (storing passwords in a recoverable format), CVE-2026-65310 (missing authentication for critical configuration endpoints), CVE-2026-65311 (unauthorized modification of logging levels), and CVE-2026-65313 (use of hard-coded credentials for x11vnc).\u003c/p\u003e\n\u003cp\u003eThese issues, impacting the Energy sector globally, stem from insecure design patterns during development and provisioning. An unauthenticated attacker can gain visibility into live process data, recover credentials, or establish remote control over engineering workstations via VNC. These vulnerabilities highlight the risk of exposed ICS management interfaces and the necessity for robust authentication and secure credential management within operational technology (OT) environments. ANDRITZ has released versions V8.00.00 and V8.15.00 to mitigate these risks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for unauthorized access to process values, potential credential harvesting across the enterprise, and the concealment of malicious activity by disabling system logging. In the context of the Energy sector, these impacts pose significant operational risks, including the potential for unauthorized process manipulation or the compromise of sensitive engineering infrastructure, affecting organizations globally that rely on these ANDRITZ platforms.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all ANDRITZ HIPASE-250 and 250 SCALA instances to version V8.15.00 immediately as specified in the vendor remediation.\u003c/li\u003e\n\u003cli\u003eAudit network segmentation to ensure management interfaces for HIPASE-250 and 250 SCALA are not reachable from untrusted or public networks to mitigate the risk of unauthenticated access (CVE-2026-65310).\u003c/li\u003e\n\u003cli\u003eReview all engineering workstations for VNC services and change default passwords immediately to address CVE-2026-65313.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for unauthorized or anomalous access to configuration endpoints and log-level adjustment endpoints, particularly targeting the specific undocumented interfaces described in CVE-2026-65311.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:52:52Z","date_published":"2026-08-13T16:52:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-andritz-hipase-vulnerabilities/","summary":"ANDRITZ HIPASE-250 and 250 SCALA devices (versions \u003c=7.20) contain multiple high-severity vulnerabilities, including hard-coded credentials, missing authentication on critical functions, and insecure password storage, enabling potential remote exploitation.","title":"Multiple Vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA","url":"https://feed.craftedsignal.io/briefs/2026-08-andritz-hipase-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-65311","version":"https://jsonfeed.org/version/1.1"}