ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to recover all stored
passwords.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.andritz.com/ |
|
History
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords. | |
| Title | Storage of passwords in a reversible format | |
| Weaknesses | CWE-257 CWE-327 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2026-07-31T16:36:34.930Z
Reserved: 2026-07-21T20:33:52.962Z
Link: CVE-2026-65309
Updated: 2026-07-31T16:36:27.813Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T18:45:04Z