The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes an undocumented endpoint that changes
the server's logging level and target without requiring
authentication. A remote, unauthenticated attacker with network
access to the service may suppress audit logging, potentially
concealing other activity on the system.
References
| Link | Resource |
|---|---|
| https://www.andritz.com/ |
Configurations
No configuration.
History
31 Jul 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-31 09:16
Updated : 2026-07-31 17:16
NVD link : CVE-2026-65311
Mitre link : CVE-2026-65311
CVE.ORG link : CVE-2026-65311
JSON object : View
Products Affected
No product.
