ANDRITZ HIPASE-250是ANDRITZ公司开源的一款工业控制产品。 ANDRITZ HIPASE-250 7.20及之前版本和250 SCALA 7.20及之前版本存在信任管理问题漏洞,该漏洞源于安装过程中使用固定硬编码的x11vnc密码,且所有工作站均使用相同凭据,可能导致具有相邻网络访问权限并知晓密码的攻击者获取VNC访问权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ANDRITZ | 250 SCALA | ≤ 7.20 |
affected |
8.15 |
unaffected | ||
| ANDRITZ | HIPASE-250 | ≤ 7.20 |
affected |
8.15 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ANDRITZ | HIPASE-250 | 0 ~ 7.20 | - |
|
| ANDRITZ | 250 SCALA | 0 ~ 7.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65309 | 7.5 HIGH | Storage of passwords in a reversible format |
| CVE-2026-65310 | 7.5 HIGH | Missing authentication and permissive CORS policy |
| CVE-2026-65311 | 5.3 MEDIUM | Missing authentication for logging-configuration endpoint |
No comments yet