Executive brief
ANDRITZ HIPASE-250, a system used for automation and control in industrial environments like hydropower plants, contains a security flaw in its default configuration. The system's data and configuration interface is accessible over the network without requiring a password. This allows an unauthorized person to view sensitive server settings and live operational data, potentially exposing details about industrial processes and system health.
Technical details
The vulnerability stems from a lack of authentication (CWE-306) on critical data and configuration endpoints in the default setup of ANDRITZ HIPASE-250 and 250 SCALA. Additionally, the system implements a permissive Cross-Origin Resource Sharing (CORS) policy (CWE-942) on every response. An unauthenticated attacker with network reachability to the device can exploit these weaknesses to exfiltrate live process values and internal server configurations. The issue affects versions up to and including 7.20; version 7.40 is reported as unaffected.
Affected products
- ANDRITZ HIPASE-250 <= 7.20
- ANDRITZ 250 SCALA <= 7.20
Timeline
- 2026-07-31: advisory: NVD publication date
- 2026-07-31: disclosed: Initial disclosure by CyberDanube