CVE-2026-65313
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
31/07/2026
Last modified:
31/07/2026
Description
A provisioning script used when installing HIPASE-250 (formerly 250<br />
SCALA) engineering workstations sets a fixed, hard-coded x11vnc<br />
password. Because the same credential is applied to every workstation<br />
provisioned this way, an attacker with adjacent-network access who<br />
knows the password can gain VNC access to affected workstations.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH



