Executive brief
ANDRITZ HIPASE-250, a protection and control device used in power plants and industrial automation, contains a security flaw in its web server. An unauthorized person can access a hidden setting to change or disable the system's activity logs. This could allow an attacker to hide their tracks while performing other malicious actions, making it difficult for operators to detect a security breach.
Technical details
A vulnerability exists in the HTTP server component of ANDRITZ HIPASE-250 and 250 SCALA due to missing authentication for a critical function (CWE-306). The software exposes an undocumented endpoint that allows a remote, unauthenticated attacker with network access to the service to modify the server's logging level and destination. By suppressing audit logging, an attacker can effectively hide their presence and subsequent actions on the system. The vulnerability is present in versions up to and including 7.20, and is addressed in version 8.00.
Affected products
- ANDRITZ HIPASE-250 <= 7.20
- ANDRITZ 250 SCALA <= 7.20
Timeline
- 2026-07-31: advisory: NVD publication date
- 2026-07-31: disclosed: Initial disclosure by CyberDanube