Missing authentication and permissive CORS policy
Summary
| CVE | CVE-2026-65310 |
|---|---|
| State | PUBLISHED |
| Assigner | CyberDanube |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-31 09:16:58 UTC |
| Updated | 2026-07-31 17:16:34 UTC |
| Description | ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-306 | CWE-942 | CWE-306 CWE-306 Missing authentication for critical function | CWE-942 CWE-942 Permissive cross-domain security policy with untrusted domains
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | ANDRITZ | HIPASE-250 | affected 7.20 custom | Not specified |
| CNA | ANDRITZ | HIPASE-250 | unaffected 7.40 | Not specified |
| CNA | ANDRITZ | 250 SCALA | affected 7.20 custom | Not specified |
| CNA | ANDRITZ | 250 SCALA | unaffected 7.40 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.andritz.com | [email protected] | www.andritz.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Duc Anh Nguyen (NTCS OT Penetration Testing Team) (en)
CNA: Ta Duc Thien (NTCS OT Penetration Testing Team) (en)
There are currently no legacy QID mappings associated with this CVE.