CVE-2026-65313CWE-1392CWE-798hardcoded-credentials

CVE-2026-65313

High · published July 31, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
7.2
In the wild
Unconfirmed
What it is

A provisioning script used when installing HIPASE-250 (formerly 250

SCALA) engineering workstations sets a fixed, hard-coded x11vnc

password. Because the same credential is applied to every workstation

provisioned this way, an attacker with adjacent-network access who

knows the password can gain VNC access to affected workstations.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00176 · 7.2th percentile
Weaknesses
CWE-1392 · Use of Default Credentials; CWE-798 · Use of Hard-coded Credentials
Published
2026-07-31T13:16Z
References (1)
EPSS history
Timeline
  • 31 JUL 07:34Z
    Use of hard-coded VNC credentials in the engineering-workstation provisioning
    cvelistv5