ANDRITZ HIPASE-250 and 250 SCALA

Summary

Multiple vulnerabilities have been identified in ANDRITZ HIPASE-250 and 250 SCALA systems, affecting versions up to 7.20. Successful exploitation could allow attackers to read sensitive data or gain access to affected workstations by recovering stored passwords or capturing network traffic.

IFF Assessment

FOE

These vulnerabilities allow attackers to recover stored passwords, posing a significant risk to system security and data confidentiality.

Severity

8.1 High

Defender Context

Defenders should prioritize patching or updating ANDRITZ HIPASE-250 and 250 SCALA systems to the latest versions to mitigate these critical vulnerabilities. The presence of recoverable passwords and hard-coded credentials highlights the importance of secure coding practices and robust authentication mechanisms in industrial control systems.

Read Full Story →