Security Advisory

CVE-2026-65310

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-31 07:26:29
Last updated 2026-07-31 16:34:44
Assigner CyberDanube
CVSS score not scored
State PUBLISHED

Description

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.