ANDRITZ HIPASE-250 and 250 SCALA

Plan PatchCVSS 8.1ICS-CERT ICSA-26-225-05Aug 13, 2026
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

ANDRITZ HIPASE-250 and 250 SCALA versions 7.20 and earlier contain hard-coded credentials and insufficient authentication mechanisms (CWE-257, CWE-306, CWE-798) that allow unauthenticated local network access to read data from the device and potentially access connected workstations. ANDRITZ has released firmware version V8.00.00 (December 2024) and V8.15.00 (July 2026) for HIPASE-250. No fix is available for the 250 SCALA component.

What this means
What could happen
An attacker on the local network could read sensitive data from the HIPASE-250 device or compromise connected engineering workstations, potentially exposing control system configuration or process parameters.
Who's at risk
This affects water utilities and other process industries using ANDRITZ HIPASE-250 pulp mill control systems (versions 7.20 and earlier) and the 250 SCALA software component. Engineering and operations staff with workstations accessing these systems are at risk of credential compromise.
How it could be exploited
An attacker with local network access to a HIPASE-250 device (no credentials required) can exploit weak credential storage or authentication bypass flaws to access the device and read data, or use this access to pivot to connected workstations running the software.
Prerequisites
  • Local network access to the HIPASE-250 device (Ethernet/LAN)
  • Device running firmware version 7.20 or earlier
No authentication requiredLocal network access requiredWeak credential storage (CWE-798)No fix planned for 250 SCALA component
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
1 with fix1 EOL
ProductAffected VersionsFix Status
HIPASE-250≤ 7.20Fix available
250 SCALA≤ 7.20No fix (EOL)
Remediation & Mitigation
0/3
Do now
0/1
HIPASE-250
WORKAROUNDIf firmware update cannot be scheduled immediately, restrict network access to HIPASE-250 devices to only authorized engineering workstations using network segmentation or firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HIPASE-250
HOTFIXUpdate HIPASE-250 devices to firmware version V8.15.00 or later
Mitigations - no patch available
0/1
250 SCALA has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGSegregate HIPASE-250 devices on a separate VLAN or network segment from general IT infrastructure and untrusted networks
API: /api/v1/advisories/7a0f0d47-719e-4358-a2ef-7d99052ec308

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

ANDRITZ HIPASE-250 and 250 SCALA | CVSS 8.1 - OTPulse