A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjacent-network access who
knows the password can gain VNC access to affected workstations.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.andritz.com/ |
|
History
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations. | |
| Title | Use of hard-coded VNC credentials in the engineering-workstation provisioning | |
| Weaknesses | CWE-1392 CWE-798 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2026-07-31T16:32:44.345Z
Reserved: 2026-07-21T20:33:52.962Z
Link: CVE-2026-65313
Updated: 2026-07-31T16:32:40.136Z
No data.
No data.
OpenCVE Enrichment
No data.