Lucene search

K
cve[email protected]CVE-2017-7928
HistoryAug 07, 2017 - 8:29 a.m.

CVE-2017-7928

2017-08-0708:29:00
CWE-284
web.nvd.nist.gov
35
cve-2017-7928
improper access control
sel
security gateway
nat port forwarding
unauthorized communications
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.9%

An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R204, R204-V1. The device does not properly enforce access control while configured for NAT port forwarding, which may allow for unauthorized communications to downstream devices.

Affected configurations

NVD
Node
selincsel-3620_firmwareMatchr202
OR
selincsel-3620_firmwareMatchr203
OR
selincsel-3620_firmwareMatchr203-v
OR
selincsel-3620_firmwareMatchr203-v1
OR
selincsel-3620_firmwareMatchr204
OR
selincsel-3620_firmwareMatchr204-v1
AND
selincsel-3620Match-
Node
selincsel-3622_firmwareMatchr202
OR
selincsel-3622_firmwareMatchr203
OR
selincsel-3622_firmwareMatchr203-v
OR
selincsel-3622_firmwareMatchr203-v1
OR
selincsel-3622_firmwareMatchr204
OR
selincsel-3622_firmwareMatchr204-v1
AND
selincsel-3622Match-

CNA Affected

[
  {
    "product": "Schweitzer Engineering Laboratories, Inc. SEL-3620 and SEL-3622",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Schweitzer Engineering Laboratories, Inc. SEL-3620 and SEL-3622"
      }
    ]
  }
]

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.9%

Related for CVE-2017-7928