The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes an undocumented endpoint that changes
the server's logging level and target without requiring
authentication. A remote, unauthenticated attacker with network
access to the service may suppress audit logging, potentially
concealing other activity on the system.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.andritz.com/ |
|
History
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system. | |
| Title | Missing authentication for logging-configuration endpoint | |
| Weaknesses | CWE-284 CWE-306 CWE-532 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2026-07-31T16:33:32.293Z
Reserved: 2026-07-21T20:33:52.962Z
Link: CVE-2026-65311
Updated: 2026-07-31T16:33:18.820Z
No data.
No data.
OpenCVE Enrichment
No data.