Executive brief
ANDRITZ HIPASE-250 is an automation and control system used in industrial environments like hydropower plants. A security flaw allows user passwords to be stored and sent in a format that can be easily reversed back into plain text. This means an attacker who can access the system's storage or monitor network traffic could steal credentials, potentially leading to unauthorized access and control over critical industrial operations.
Technical details
The vulnerability stems from the use of reversible password storage (CWE-257) and potentially weak or broken cryptographic algorithms (CWE-327) within the ANDRITZ HIPASE-250 (formerly 250 SCALA) platform. Instead of utilizing industry-standard one-way salted hashes, the system stores and transmits credentials in a format that can be decrypted or reversed. An unauthenticated attacker with network access can capture these credentials via traffic sniffing, or an attacker with file system access can recover them from the credential store. This flaw is present in versions up to and including 7.20; version 7.50 is reported as unaffected.
Affected products
- ANDRITZ HIPASE-250 <= 7.20
- ANDRITZ 250 SCALA <= 7.20
Timeline
- 2026-07-31: advisory: NVD publication date
- 2026-07-31: disclosed: Reported by CyberDanube