Show filters
47 Total Results
Displaying 1-10 of 47
Sort by:
Attacker Value
Unknown
CVE-2023-34390
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to create a denial of service against the system and locking out services.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-34389
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An allocation of resources without limits or throttling vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to make the system unavailable for an indefinite amount of time.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-34388
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-31177
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the Schweitzer Engineering Laboratories SEL-451 could allow an attacker to craft a link that could execute arbitrary code on a victim's system.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-31176
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated remote attacker to brute-force session tokens and bypass authentication.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-2267
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An Improper Input Validation vulnerability in Schweitzer Engineering Laboratories SEL-411L could allow an attacker to perform reflection attacks against an authorized and authenticated user.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-2266
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An Improper neutralization of input during web page generation in the Schweitzer Engineering Laboratories SEL-411L could allow an attacker to generate cross-site scripting based attacks against an authorized and authenticated user.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-2265
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-2264
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
An improper input validation vulnerability in the Schweitzer Engineering Laboratories SEL-411L could allow a malicious actor to manipulate authorized users to click on a link that could allow undesired behavior.
See product Instruction Manual Appendix A dated 20230830 for more details.
0
Attacker Value
Unknown
CVE-2023-34392
Disclosure Date: August 31, 2023 (last updated October 08, 2023)
A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator.
See Instruction Manual Appendix A and Appendix E dated 20230615 for more details.
This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20.
0