---
id: CVE-2026-65310
title: |-
  ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
  of affected versions, exposes its data and configuration endpoint
  without any authentication and permissive CORS on every response
summary: |-
  ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
  of affected versions, exposes its data and configuration endpoint
  without any authentication and permissive CORS on every response. An
  unauthenticated attacker with ne…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
  - CWE-942
published: '2026-07-31'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-65310'
references:
  - url: 'https://www.andritz.com/'
    label: office@cyberdanube.com
tags:
  - nvd
epss: 0.005
epssPercentile: 0.40225
ingestedAt: '2026-08-29T12:36:25.996Z'
---

## Overview

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network access can read live process
values and server configuration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
