Our takeCISA reports active exploitation of multiple vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA <=7.20 that let attackers read device data or access workstations. Patch immediately if you run these ICS systems.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Update ANDRITZ HIPASE-250 and 250 SCALA to a version higher than 7.20 if you run these systems; successful exploitation lets attackers read device data or access workstations.
What this means for you — Lean IT orgs:If you run ANDRITZ HIPASE-250 or 250 SCALA software, update it past version 7.20 right away; most teams without dedicated IT can ask their equipment vendor or integrator to handle the update.
What this means for you — MSP:Check client environments for ANDRITZ HIPASE-250 or 250 SCALA <=7.20 and update them; exploitation allows data reads or workstation access.
What this means for you — Researcher:Review the CISA advisory and CSAF files for the four CVEs in ANDRITZ HIPASE-250 and 250 SCALA <=7.20; test for data-read and workstation-access impacts in affected environments.