Security Flaws Found in ANDRITZ HIPASE-250 and 250 SCALA Devices Used in Energy Sector
CISA has issued an advisory warning of several vulnerabilities affecting ANDRITZ HIPASE-250 and 250 SCALA devices, versions 7.20 and earlier. These products are used worldwide, primarily in the energy sector, and are manufactured by the Austria-based company ANDRITZ.
The vulnerabilities include storing passwords in a recoverable format, missing authentication for critical functions, and the use of hard-coded credentials. Together, these issues carry a high severity rating (CVSS v3 score of 8.1) and could allow an attacker to read data from the affected device or gain unauthorised access to connected workstations.
While this advisory is primarily targeted at energy sector operators using these specific devices, it serves as a broader reminder for all businesses relying on industrial or specialised equipment: outdated password practices and hard-coded credentials remain common and dangerous weaknesses in connected devices.