PatchSiren

ANDRITZ CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ANDRITZ CVE published 2026-07-31

CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 exposes an undocumented endpoint that allows changing the server's logging level and target without requiring authentication. This vulnerability, CVE-2026-65311, has a CVSS score of 5.3 and is classified as MEDIUM severity. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity [truncated]

HIGH ANDRITZ CVE published 2026-07-31

CVE-2026-65310

ANDRITZ HIPASE-250, in its default configuration, exposes its data and configuration endpoint without any authentication and with permissive CORS on every response. This allows an unauthenticated attacker with network access to read live process values and server configuration. The vulnerability affects ANDRITZ HIPASE-250 systems, and defenders should focus on securing the data and configuration endpoint. [truncated]