CVE-2026-65309

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.
References
Link Resource
https://www.andritz.com/
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 08:16

Updated : 2026-08-28 15:28


NVD link : CVE-2026-65309

Mitre link : CVE-2026-65309

CVE.ORG link : CVE-2026-65309


JSON object : View

Products Affected

No product.

CWE
CWE-257

Storing Passwords in a Recoverable Format

CWE-327

Use of a Broken or Risky Cryptographic Algorithm