Executive Summary
In August 2026, multiple vulnerabilities were identified in ANDRITZ HIPASE-250 and 250 SCALA devices, including storing passwords in a recoverable format, missing authentication for critical functions, and the use of hard-coded credentials. These flaws could allow attackers to read sensitive data or gain unauthorized access to affected workstations. ANDRITZ has released updates to address these issues and recommends users upgrade to version V8.15.00.
The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems, especially in the energy sector. Organizations must prioritize timely updates and robust security measures to protect against potential exploits targeting such weaknesses.
Why This Matters Now
The identification of these vulnerabilities highlights the ongoing risks in industrial control systems, emphasizing the need for immediate action to prevent potential exploitation and ensure the security of critical infrastructure.
Attack Path Analysis
An attacker exploited multiple vulnerabilities in the ANDRITZ HIPASE-250 and 250 SCALA systems, including the use of hard-coded credentials and missing authentication for critical functions, to gain unauthorized access. This access allowed the attacker to escalate privileges by exploiting the system's default configurations and lack of proper access controls. Subsequently, the attacker moved laterally within the network, accessing other connected systems and devices. They established command and control by modifying system configurations and suppressing audit logs to conceal their activities. The attacker exfiltrated sensitive data by leveraging the system's vulnerabilities to read and transmit data without detection. Finally, the attacker caused significant impact by potentially disrupting operations and compromising the integrity of the industrial control systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attacker exploited hard-coded credentials (CVE-2026-65313) and missing authentication for critical functions (CVE-2026-65310) to gain unauthorized access to the ANDRITZ HIPASE-250 and 250 SCALA systems.
Related CVEs
CVE-2026-65309
CVSS 7.5ANDRITZ HIPASE-250 and 250 SCALA store and transmit user passwords using a reversible format, allowing attackers to recover all stored passwords.
Affected Products:
ANDRITZ HIPASE-250 – <=7.20
ANDRITZ 250 SCALA – <=7.20
Exploit Status:
no public exploitCVE-2026-65310
CVSS 7.5ANDRITZ HIPASE-250 and 250 SCALA expose data and configuration endpoints without authentication, allowing unauthenticated attackers to read live process values and server configuration.
Affected Products:
ANDRITZ HIPASE-250 – <=7.20
ANDRITZ 250 SCALA – <=7.20
Exploit Status:
no public exploitCVE-2026-65311
CVSS 5.3ANDRITZ HIPASE-250 and 250 SCALA expose an undocumented endpoint that changes the server's logging level and target without authentication, allowing attackers to suppress audit logging.
Affected Products:
ANDRITZ HIPASE-250 – <=7.20
ANDRITZ 250 SCALA – <=7.20
Exploit Status:
no public exploitCVE-2026-65313
CVSS 8.1ANDRITZ HIPASE-250 and 250 SCALA use a hard-coded x11vnc password during workstation provisioning, allowing attackers with adjacent-network access to gain VNC access to affected workstations.
Affected Products:
ANDRITZ HIPASE-250 – <=7.20
ANDRITZ 250 SCALA – <=7.20
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Unsecured Credentials: Credentials In Files
Valid Accounts
External Remote Services
Application Layer Protocol: Web Protocols
Impair Defenses: Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Password-Based Authentication
Control ID: IA-5(1)
PCI DSS 4.0 – Secure Authentication Features
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 6
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Critical infrastructure vulnerabilities in ANDRITZ HIPASE-250 systems expose energy sector operations to unauthorized access, data theft, and potential operational disruption through authentication bypasses.
Utilities
Hard-coded credentials and missing authentication in industrial control systems create severe risks for utility infrastructure, enabling remote attackers to access critical operational data.
Industrial Automation
HIPASE-250 vulnerabilities compromise industrial automation security through recoverable password storage and unauthenticated endpoints, threatening manufacturing process integrity and confidentiality.
Manufacturing
Multiple authentication weaknesses in ANDRITZ industrial systems expose manufacturing environments to network-based attacks, potentially disrupting production operations and compromising sensitive process data.
Sources
- ANDRITZ HIPASE-250 and 250 SCALAhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-225-05Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to exploit vulnerabilities, escalate privileges, and move laterally within the network, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing Aviatrix CNSF could have limited unauthorized access by enforcing identity-aware policies, thereby reducing the likelihood of exploiting hard-coded credentials and missing authentication mechanisms.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could have restricted privilege escalation by enforcing least-privilege access, thereby limiting the attacker's ability to exploit default configurations and inadequate access controls.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could have limited lateral movement by enforcing micro-segmentation, thereby reducing the attacker's ability to access other systems using compromised credentials.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could have reduced the effectiveness of command and control by providing real-time monitoring and alerting on unauthorized configuration changes and log suppression.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could have limited data exfiltration by controlling outbound traffic and detecting unauthorized data transmissions.
Aviatrix Zero Trust CNSF could have reduced the operational impact by limiting the attacker's ability to disrupt systems and compromise integrity through enforced segmentation and access controls.
Impact at a Glance
Affected Business Functions
- Power Generation Control
- Grid Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of operational data and system configurations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and enforce least privilege access.
- • Deploy East-West Traffic Security controls to monitor and control internal network communications.
- • Utilize Encrypted Traffic (HPE) to protect data in transit and prevent unauthorized data access.
- • Establish Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.



