CVE-2026-65313Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

0.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-798CWE-1392

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-13: 1Technical Details · 2026-08-13: 108-13
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Windows Forum@windowsforum
    Disclosure

    ⚠️ A shared VNC password is a terrible access-control strategy—especially for HIPASE workstations. CISA’s warning is a reminder that “not Windows” doesn’t mean “not urgent.” https://windowsforum.com/security-alerts.84/cve-2026-65313-shared-vnc-password-exposes-hipase-workstations.442821/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #IndustrialControlSystems #ScadaSecurity #CisaAlerts #Hipase250 https://t.co/X8hHjQhcud

    Post summary

    CISA warns that shared VNC passwords expose HIPASE workstations, highlighting CVE-2026-65313 as an access‑control flaw, but provides no PoC, exploit, active‑attack claim, or patch information.

    0000046
    1.3K followersView on X

Explore more