CVE-2026-65311
Received Received - Intake

Unauthenticated Logging Level Change in ANDRITZ HIPASE-250

Vulnerability report for CVE-2026-65311, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: CyberDanube

Description

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
andritz hipase-250 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The HTTP server in ANDRITZ HIPASE-250 has an undocumented endpoint that allows unauthenticated users to change the server's logging level and target. This could let attackers disable audit logging to hide malicious activity.

Detection Guidance

Check for unauthorized changes to logging settings by inspecting HTTP requests to the undocumented endpoint. Monitor network traffic for unusual POST requests targeting the server's logging configuration. Verify if audit logs are being suppressed or altered without legitimate administrative actions.

Impact Analysis

An attacker could exploit this to suppress system logs, making it harder to detect or investigate security incidents. This could allow further unauthorized actions to go unnoticed.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by preventing proper audit logging. Regulations often require detailed logs for security monitoring and compliance reporting.

Mitigation Strategies

Restrict network access to the HTTP server component to trusted sources only. Update to a patched version of ANDRITZ HIPASE-250 if available. Disable or remove the undocumented endpoint if no longer required. Enable strict authentication for all administrative functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65311. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart