{"id":"CVE-2026-65310","title":"ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response","summary":"ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response. An\nunauthenticated attacker with ne…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-306","CWE-942"],"published":"2026-07-31","updated":"2026-08-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-65310","references":[{"url":"https://www.andritz.com/","label":"office@cyberdanube.com"}],"tags":["nvd"],"epss":0.00318,"epssPercentile":0.25015,"ingestedAt":"2026-08-29T12:36:25.996Z","slug":"CVE-2026-65310","body":"## Overview\n\nANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response. An\nunauthenticated attacker with network access can read live process\nvalues and server configuration.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}