Critical Credential Exposure Vulnerabilities (CVE‑2026‑65309‑65313) in ANDRITZ HIPASE‑250/250 SCALA Threaten Industrial Control Systems
What It Is – CISA has identified four high‑severity CVEs (CVE‑2026‑65309, ‑65310, ‑65311, ‑65313) in ANDRITZ HIPASE‑250 and 250 SCALA controllers. The flaws include storing passwords in a reversible format, missing authentication on critical functions, and hard‑coded credentials.
Exploitability – CVSS v3 score 8.1 (High). Exploits are publicly documented; an attacker who can read the device’s credential store or capture network traffic can recover clear‑text passwords and gain workstation access.
Affected Products – ANDRITZ HIPASE‑250 ≤ 7.20 and ANDRITZ 250 SCALA ≤ 7.20 (industrial water‑treatment and process‑control units).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Security controls require encrypted credential storage and strong authentication; reversible passwords and hard‑coded credentials constitute a direct control failure.
- Continuous evidence of patch management and credential‑policy enforcement is a key audit artifact; unpatched devices expose organizations to non‑compliance findings.
- Energy‑sector operators are increasingly required to demonstrate defensible security postures to regulators and partners; these vulnerabilities erode that trust.
Recommended Actions
- Patch immediately to ANDRITZ version V8.00.00 (or later V8.15.00).
- Inventory all HIPASE‑250/250 SCALA units and verify firmware version.
- Replace reversible password storage with salted, one‑way hashing; disable any hard‑coded accounts.
- Update SOC 2 access‑control policies to reflect the new credential‑handling requirements and capture remediation evidence for audit.
- Enable network‑traffic encryption (TLS) between controllers and workstations.
Source: CISA Advisory – ICSA‑26‑225‑05