{"api_version":"1","generated_at":"2026-07-31T21:28:49+00:00","cve":"CVE-2026-65310","urls":{"html":"https://cve.report/CVE-2026-65310","api":"https://cve.report/api/cve/CVE-2026-65310.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-65310","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-65310"},"summary":{"title":"Missing authentication and permissive CORS policy","description":"ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response. An\nunauthenticated attacker with network access can read live process\nvalues and server configuration.","state":"PUBLISHED","assigner":"CyberDanube","published_at":"2026-07-31 09:16:58","updated_at":"2026-07-31 17:16:34"},"problem_types":["CWE-306","CWE-942","CWE-306 CWE-306 Missing authentication for critical function","CWE-942 CWE-942 Permissive cross-domain security policy with untrusted domains"],"metrics":[{"version":"3.1","source":"office@cyberdanube.com","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.andritz.com/","name":"https://www.andritz.com/","refsource":"office@cyberdanube.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-65310","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65310","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"ANDRITZ","product":"HIPASE-250","version":"affected 7.20 custom","platforms":[]},{"source":"CNA","vendor":"ANDRITZ","product":"HIPASE-250","version":"unaffected 7.40","platforms":[]},{"source":"CNA","vendor":"ANDRITZ","product":"250 SCALA","version":"affected 7.20 custom","platforms":[]},{"source":"CNA","vendor":"ANDRITZ","product":"250 SCALA","version":"unaffected 7.40","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Duc Anh Nguyen (NTCS OT Penetration Testing Team)","lang":"en"},{"source":"CNA","value":"Ta Duc Thien (NTCS OT Penetration Testing Team)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-65310","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-31T16:34:22.818330Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-31T16:34:44.010Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"affected","product":"HIPASE-250","vendor":"ANDRITZ","versions":[{"lessThanOrEqual":"7.20","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"7.40"}]},{"defaultStatus":"affected","product":"250 SCALA","vendor":"ANDRITZ","versions":[{"lessThanOrEqual":"7.20","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"7.40"}]}],"credits":[{"lang":"en","type":"finder","value":"Duc Anh Nguyen (NTCS OT Penetration Testing Team)"},{"lang":"en","type":"finder","value":"Ta Duc Thien (NTCS OT Penetration Testing Team)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>&nbsp;ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response. An\nunauthenticated attacker with network access can read live process\nvalues and server configuration.</p>"}],"value":"ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response. An\nunauthenticated attacker with network access can read live process\nvalues and server configuration."}],"impacts":[{"capecId":"CAPEC-36","descriptions":[{"lang":"en","value":"CAPEC-36 Using Unpublished Interfaces or Functionality"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing authentication for critical function","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-942","description":"CWE-942 Permissive cross-domain security policy with untrusted domains","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-31T07:26:55.686Z","orgId":"7d092a75-6bbd-48c6-a15a-0297458009bc","shortName":"CyberDanube"},"references":[{"url":"https://www.andritz.com/"}],"source":{"discovery":"EXTERNAL"},"title":"Missing authentication and permissive CORS policy","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"7d092a75-6bbd-48c6-a15a-0297458009bc","assignerShortName":"CyberDanube","cveId":"CVE-2026-65310","datePublished":"2026-07-31T07:26:29.954Z","dateReserved":"2026-07-21T20:33:52.962Z","dateUpdated":"2026-07-31T16:34:44.010Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-31 09:16:58","lastModifiedDate":"2026-07-31 17:16:34","problem_types":["CWE-306","CWE-942","CWE-306 CWE-306 Missing authentication for critical function","CWE-942 CWE-942 Permissive cross-domain security policy with untrusted domains"],"metrics":{"cvssMetricV31":[{"source":"office@cyberdanube.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T16:34:22.818330Z","id":"CVE-2026-65310","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"65310","Ordinal":"1","Title":"Missing authentication and permissive CORS policy","CVE":"CVE-2026-65310","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"65310","Ordinal":"1","NoteData":"ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response. An\nunauthenticated attacker with network access can read live process\nvalues and server configuration.","Type":"Description","Title":"Missing authentication and permissive CORS policy"}]}}}