As cited
Copy frozen at (site build).
vulnerabilities
ANDRITZ HIPASE-250 and 250 SCALA
ANDRITZ HIPASE-250 and 250 SCALA devices (versions 7.20 and earlier) contain four high-severity vulnerabilities affecting energy sector critical infrastructure worldwide. These flaws enable password recovery through reversible storage, unauthenticated access to device data and configuration, suppression of audit logging, and remote VNC access via hardcoded credentials. ANDRITZ released patches in version 8.00.00 (December 2024) and version 8.15.00 (July 2026) to address these issues.
Why it matters: Energy and utilities operators running HIPASE-250 or 250 SCALA at version 7.20 or below must upgrade immediately to version 8.15.00 or later to prevent unauthorized data exfiltration, configuration tampering, and direct workstation access by remote attackers.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
ANDRITZ HIPASE-250 and 250 SCALA
ANDRITZ HIPASE-250 and 250 SCALA devices (versions 7.20 and earlier) contain four high-severity vulnerabilities affecting energy sector critical infrastructure worldwide. These flaws enable password recovery through reversible storage, unauthenticated access to device data and configuration, suppression of audit logging, and remote VNC access via hardcoded credentials. ANDRITZ released patches in version 8.00.00 (December 2024) and version 8.15.00 (July 2026) to address these issues.
Why it matters: Energy and utilities operators running HIPASE-250 or 250 SCALA at version 7.20 or below must upgrade immediately to version 8.15.00 or later to prevent unauthorized data exfiltration, configuration tampering, and direct workstation access by remote attackers.
- Source published
- First seen by Cybersecurity Tracker