CVE-2026-65309CWE-257CWE-327
CVE-2026-65309
High · published July 31, 2026
What it is
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to recover all stored
passwords.
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00152 · 4.7th percentile
- Weaknesses
- CWE-257 · Storing Passwords in a Recoverable Format; CWE-327 · Use of a Broken or Risky Cryptographic Algorithm
- Published
- 2026-07-31T12:16Z
References (1)
EPSS history
Timeline