SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjacent-network access who
knows the password can gain VNC access to affected workstations.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.andritz.com/ |
|
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Andritz
Andritz 250 Scala Andritz hipase-250 |
|
| Vendors & Products |
Andritz
Andritz 250 Scala Andritz hipase-250 |
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations. | |
| Title | Use of hard-coded VNC credentials in the engineering-workstation provisioning | |
| Weaknesses | CWE-1392 CWE-798 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2026-07-31T16:32:44.345Z
Reserved: 2026-07-21T20:33:52.962Z
Link: CVE-2026-65313
Updated: 2026-07-31T16:32:40.136Z
Status : Received
Published: 2026-07-31T09:16:59.090
Modified: 2026-07-31T17:16:34.970
Link: CVE-2026-65313
No data.
OpenCVE Enrichment
Updated: 2026-08-02T20:33:02Z