CVE-2026-65313 PUBLISHED

Use of hard-coded VNC credentials in the engineering-workstation provisioning

Assigner: CyberDanube
Reserved: 21.07.2026 Published: 31.07.2026 Updated: 31.07.2026

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 8.1

Product Status

Vendor ANDRITZ
Product HIPASE-250
Versions Default: affected
  • affected from 0 to 7.20 (incl.)
  • Version 8.15 is unaffected
Vendor ANDRITZ
Product 250 SCALA
Versions Default: affected
  • affected from 0 to 7.20 (incl.)
  • Version 8.15 is unaffected

Credits

  • Duc Anh Nguyen (NTCS OT Penetration Testing Team) finder
  • Ta Duc Thien (NTCS OT Penetration Testing Team) finder

References

Problem Types

  • CWE-798 CWE
  • CWE-1392 Use of default credentials CWE

Impacts

  • CAPEC-70 Try Common or Default Usernames and Passwords