CVE-2026-65311 PUBLISHED

Missing authentication for logging-configuration endpoint

Assigner: CyberDanube
Reserved: 21.07.2026 Published: 31.07.2026 Updated: 31.07.2026

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor ANDRITZ
Product HIPASE-250
Versions Default: affected
  • affected from 0 to 7.20 (incl.)
  • Version 8.00 is unaffected
Vendor ANDRITZ
Product 250 SCALA
Versions Default: affected
  • affected from 0 to 7.20 (incl.)
  • Version 8.00 is unaffected

Credits

  • Duc Anh Nguyen (NTCS OT Penetration Testing Team) finder
  • Ta Duc Thien (NTCS OT Penetration Testing Team) finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE
  • CWE-532 Insertion of sensitive information into log file CWE
  • CWE-284 CWE

Impacts

  • CAPEC-36 Using Unpublished Interfaces or Functionality