CVE-2026-65313: Andritz 250 Scala

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

Affected products

  • Andritz 250 Scala: up to and including 7.20
  • Andritz Hipase-250: up to and including 7.20

Published 2026-07-31. Last modified 2026-08-28.