SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65309

HIGH · CVSS 7.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The ANDRITZ HIPASE-250 system is vulnerable due to its use of a reversible format for storing and transmitting user passwords, rather than employing a secure one-way hashing method. This flaw allows attackers to easily recover all stored passwords by accessing the credential store or intercepting network traffic. Organizations using affected versions of this system should prioritize remediation efforts to mitigate the risk of credential theft and unauthorized access.

CVE
CVE-2026-65309
Severity
HIGH
CVSS
7.5
EPSS
0.15%

Original NVD Description

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.