Executive brief
A security issue has been identified in the setup process for ANDRITZ HIPASE-250 engineering workstations, which are used in industrial automation environments. A configuration script automatically sets a identical, permanent password for remote desktop access (VNC) across all installations. This allows an attacker on the same local network to gain full remote control of the workstation, potentially disrupting industrial operations or accessing sensitive engineering data.
Technical details
The vulnerability stems from the use of hard-coded credentials (CWE-798) within a provisioning script used during the installation of ANDRITZ HIPASE-250 (formerly 250 SCALA) engineering workstations. The script configures the x11vnc service with a static password that is identical across all deployments. An unauthenticated attacker located on the same adjacent network can exploit this by connecting to the VNC service using the known password. Successful exploitation grants the attacker remote graphical access to the workstation with the privileges of the logged-in user. The issue is resolved in version 8.15.
Affected products
- ANDRITZ HIPASE-250 (formerly 250 SCALA) engineering workstations <= 7.20
Timeline
- 2026-07-31: disclosed
- 2026-07-31: advisory