CVE-2026-65313

ANDRITZ · HIPASE-250

A provisioning script in the ANDRITZ HIPASE-250 and 250 SCALA engineering workstations sets a hard-coded x11vnc password, allowing unauthorized remote access.

Executive summary

Hard-coded credentials in ANDRITZ HIPASE-250 engineering workstations create a critical security vulnerability that allows unauthorized remote access to the system.

Vulnerability

The vulnerability stems from the use of a hard-coded password for the x11vnc service, which is established during the provisioning of engineering workstations. This is an authentication-related flaw that allows attackers with local network access to gain unauthorized control.

Business impact

With a CVSS score of 8.1, this vulnerability poses a severe risk to operational technology environments. Unauthorized access to an engineering workstation can lead to the manipulation of industrial processes, loss of system control, or the compromise of sensitive operational data.

Remediation

Immediate Action: Update to version 8.15 or later, which contains the fix for the hard-coded credential issue.

Proactive Monitoring: Audit network access logs for the x11vnc service and restrict access to these workstations to authorized personnel only.

Compensating Controls: Disable the x11vnc service if it is not required for daily operations, or implement strong network segmentation to isolate the engineering workstations from untrusted segments.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

This vulnerability requires immediate attention due to the ease of exploitation once an attacker has network access. Organizations should perform an inventory of all affected workstations and ensure the upgrade to version 8.15 is executed as part of a formal maintenance window.