Description
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.
Severity (CVSS)
| Base score | 5.3 |
|---|---|
| Severity | Medium |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| Provided by | CNA |
Weaknesses
- CWE-306 — CWE-306 Missing authentication for critical function
- CWE-532 — CWE-532 Insertion of sensitive information into log file
- CWE-284 — CWE-284
Affected products
| Vendor | Product | Versions |
|---|---|---|
| ANDRITZ | HIPASE-250 | 0 to <=7.20; 8.00 |
| ANDRITZ | 250 SCALA | 0 to <=7.20; 8.00 |
References
Generated from the official CVE List on 01 Aug 2026 07:04 UTC.