HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Credential Exposure Vulnerabilities (CVE‑2026‑65309‑65313) in ANDRITZ HIPASE‑250/250 SCALA Threaten Industrial Control Systems

CISA reports four high‑severity CVEs in ANDRITZ HIPASE‑250 and 250 SCALA controllers that expose passwords and allow unauthenticated access. For SOC 2‑compliant organizations, the flaws highlight gaps in credential‑management controls and the need for rapid patching and evidence collection.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Critical Credential Exposure Vulnerabilities (CVE‑2026‑65309‑65313) in ANDRITZ HIPASE‑250/250 SCALA Threaten Industrial Control Systems

What It Is – CISA has identified four high‑severity CVEs (CVE‑2026‑65309, ‑65310, ‑65311, ‑65313) in ANDRITZ HIPASE‑250 and 250 SCALA controllers. The flaws include storing passwords in a reversible format, missing authentication on critical functions, and hard‑coded credentials.

Exploitability – CVSS v3 score 8.1 (High). Exploits are publicly documented; an attacker who can read the device’s credential store or capture network traffic can recover clear‑text passwords and gain workstation access.

Affected Products – ANDRITZ HIPASE‑250 ≤ 7.20 and ANDRITZ 250 SCALA ≤ 7.20 (industrial water‑treatment and process‑control units).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Security controls require encrypted credential storage and strong authentication; reversible passwords and hard‑coded credentials constitute a direct control failure.
  • Continuous evidence of patch management and credential‑policy enforcement is a key audit artifact; unpatched devices expose organizations to non‑compliance findings.
  • Energy‑sector operators are increasingly required to demonstrate defensible security postures to regulators and partners; these vulnerabilities erode that trust.

Recommended Actions

  • Patch immediately to ANDRITZ version V8.00.00 (or later V8.15.00).
  • Inventory all HIPASE‑250/250 SCALA units and verify firmware version.
  • Replace reversible password storage with salted, one‑way hashing; disable any hard‑coded accounts.
  • Update SOC 2 access‑control policies to reflect the new credential‑handling requirements and capture remediation evidence for audit.
  • Enable network‑traffic encryption (TLS) between controllers and workstations.

Source: CISA Advisory – ICSA‑26‑225‑05

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-05

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →