CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

ANDRITZ HIPASE-250 and 250 SCALA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4394

As cited

Copy frozen at (site build).

vulnerabilities

ANDRITZ HIPASE-250 and 250 SCALA

ANDRITZ HIPASE-250 and 250 SCALA devices (versions 7.20 and earlier) contain four high-severity vulnerabilities affecting energy sector critical infrastructure worldwide. These flaws enable password recovery through reversible storage, unauthenticated access to device data and configuration, suppression of audit logging, and remote VNC access via hardcoded credentials. ANDRITZ released patches in version 8.00.00 (December 2024) and version 8.15.00 (July 2026) to address these issues.

Why it matters: Energy and utilities operators running HIPASE-250 or 250 SCALA at version 7.20 or below must upgrade immediately to version 8.15.00 or later to prevent unauthorized data exfiltration, configuration tampering, and direct workstation access by remote attackers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

ANDRITZ HIPASE-250 and 250 SCALA

ANDRITZ HIPASE-250 and 250 SCALA devices (versions 7.20 and earlier) contain four high-severity vulnerabilities affecting energy sector critical infrastructure worldwide. These flaws enable password recovery through reversible storage, unauthenticated access to device data and configuration, suppression of audit logging, and remote VNC access via hardcoded credentials. ANDRITZ released patches in version 8.00.00 (December 2024) and version 8.15.00 (July 2026) to address these issues.

Why it matters: Energy and utilities operators running HIPASE-250 or 250 SCALA at version 7.20 or below must upgrade immediately to version 8.15.00 or later to prevent unauthorized data exfiltration, configuration tampering, and direct workstation access by remote attackers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary