{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-65310",
        "assignerOrgId": "7d092a75-6bbd-48c6-a15a-0297458009bc",
        "state": "PUBLISHED",
        "assignerShortName": "CyberDanube",
        "dateReserved": "2026-07-21T20:33:52.962Z",
        "datePublished": "2026-07-31T07:26:29.954Z",
        "dateUpdated": "2026-07-31T16:34:44.010Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "7d092a75-6bbd-48c6-a15a-0297458009bc",
                "shortName": "CyberDanube",
                "dateUpdated": "2026-07-31T07:26:55.686Z"
            },
            "title": "Missing authentication and permissive CORS policy",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-306",
                            "description": "CWE-306 Missing authentication for critical function",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-942",
                            "description": "CWE-942 Permissive cross-domain security policy with untrusted domains",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-36",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-36 Using Unpublished Interfaces or Functionality"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "ANDRITZ",
                    "product": "HIPASE-250",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "7.20",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "7.40"
                        }
                    ],
                    "defaultStatus": "affected"
                },
                {
                    "vendor": "ANDRITZ",
                    "product": "250 SCALA",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "7.20",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "7.40"
                        }
                    ],
                    "defaultStatus": "affected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response. An\nunauthenticated attacker with network access can read live process\nvalues and server configuration.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>&nbsp;ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration\nof affected versions, exposes its data and configuration endpoint\nwithout any authentication and permissive CORS on every response. An\nunauthenticated attacker with network access can read live process\nvalues and server configuration.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.andritz.com/"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "availabilityImpact": "NONE",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.5,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Duc Anh Nguyen (NTCS OT Penetration Testing Team)",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "Ta Duc Thien (NTCS OT Penetration Testing Team)",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-31T16:34:22.818330Z",
                                "id": "CVE-2026-65310",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-31T16:34:44.010Z"
                }
            }
        ]
    }
}