Description
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes an undocumented endpoint that changes
the server's logging level and target without requiring
authentication. A remote, unauthenticated attacker with network
access to the service may suppress audit logging, potentially
concealing other activity on the system.
Published: 2026-07-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The HTTP server of ANDRITZ HIPASE‑250 (formerly 250 SCALA) contains an undocumented endpoint that allows an attacker to alter the logging level and target without authentication. This flaw, represented by CWE‑284, CWE‑306, and CWE‑532, lets a remote attacker suppress audit logging and thereby conceal other malicious activity, reducing system visibility and facilitating further compromise.

Affected Systems

ANDRITZ HIPASE‑250 and the legacy 250 SCALA products are affected. The vulnerability exists in all currently supported versions of the HTTP server component, as no specific version ranges are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, but the EPSS score of less than 1% shows that exploitation is believed to be unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires network access to the HTTP service and can be performed by an unauthenticated attacker simply by sending a request to the undocumented endpoint. While it does not provide code execution, it permits an attacker to obscure their actions by disabling audit logs, thus escalating the risk of remaining undetected.

Generated by OpenCVE AI on August 2, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ANDRITZ patch that requires authentication for the logging-configuration endpoint.
  • Configure firewall or network segmentation to restrict access to the HIPASE‑250 HTTP service to trusted hosts only.
  • Enable external monitoring or alerting for any changes to logging configuration or abrupt silence in audit logs.

Generated by OpenCVE AI on August 2, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.andritz.com/ cve-icon cve-icon
History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Andritz
Andritz 250 Scala
Andritz hipase-250
Vendors & Products Andritz
Andritz 250 Scala
Andritz hipase-250

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.
Title Missing authentication for logging-configuration endpoint
Weaknesses CWE-284
CWE-306
CWE-532
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Andritz 250 Scala Hipase-250
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-31T16:33:32.293Z

Reserved: 2026-07-21T20:33:52.962Z

Link: CVE-2026-65311

cve-icon Vulnrichment

Updated: 2026-07-31T16:33:18.820Z

cve-icon NVD

Status : Received

Published: 2026-07-31T09:16:58.960

Modified: 2026-07-31T17:16:34.860

Link: CVE-2026-65311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:33:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-532

    Insertion of Sensitive Information into Log File