SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65313

HIGH · CVSS 8.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

A vulnerability exists in the provisioning script for HIPASE-250 engineering workstations, which uses a hard-coded x11vnc password applicable to all instances. This flaw allows an attacker with adjacent-network access to exploit the fixed credential, potentially gaining unauthorized VNC access to the workstations. Organizations using HIPASE-250 should prioritize addressing this vulnerability to mitigate the risk of unauthorized access.

CVE
CVE-2026-65313
Severity
HIGH
CVSS
8.1
EPSS
0.18%

Original NVD Description

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.