CVE-2026-65309CWE-257CWE-327

CVE-2026-65309

High · published July 31, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
4.7
In the wild
Unconfirmed
What it is

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores

and transmits user passwords using a reversible format instead of a

one-way password hash. This allows an attacker able to read the

credential store or capture network traffic to recover all stored

passwords.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00152 · 4.7th percentile
Weaknesses
CWE-257 · Storing Passwords in a Recoverable Format; CWE-327 · Use of a Broken or Risky Cryptographic Algorithm
Published
2026-07-31T12:16Z
References (1)
EPSS history
Timeline
  • 31 JUL 07:17Z
    Storage of passwords in a reversible format
    cvelistv5