CVE-2026-65309: Andritz 250 Scala

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.

Affected products

  • Andritz 250 Scala: up to and including 7.20
  • Andritz Hipase-250: up to and including 7.20

Published 2026-07-31. Last modified 2026-08-28.