Lucene search

K
nvd[email protected]NVD:CVE-2023-2265
HistoryNov 30, 2023 - 5:15 p.m.

CVE-2023-2265

2023-11-3017:15:07
CWE-1021
web.nvd.nist.gov
schweitzer engineering laboratories
ui layers
frames
clickjacking
authenticated user
unauthorized access

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

20.5%

AnΒ Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user.

See product Instruction Manual Appendix A dated 20230830 for more details.

Affected configurations

Nvd
Node
selincsel-411l_firmwareRanger118-v0–r118-v4
OR
selincsel-411l_firmwareRanger119-v0–r119-v5
OR
selincsel-411l_firmwareRanger120-v0–r120-v6
OR
selincsel-411l_firmwareRanger121-v0–r121-v3
OR
selincsel-411l_firmwareRanger122-v0–r122-v3
OR
selincsel-411l_firmwareRanger123-v0–r123-v3
OR
selincsel-411l_firmwareRanger124-v0–r124-v3
OR
selincsel-411l_firmwareRanger125-v0–r125-v3
OR
selincsel-411l_firmwareRanger126-v0–r126-v4
OR
selincsel-411l_firmwareRanger127-v0–r127-v2
OR
selincsel-411l_firmwareMatchr128-v0
OR
selincsel-411l_firmwareMatchr129-v0
AND
selincsel-411lMatch-
VendorProductVersionCPE
selincsel-411l_firmware*cpe:2.3:o:selinc:sel-411l_firmware:*:*:*:*:*:*:*:*
selincsel-411l_firmwarer128-v0cpe:2.3:o:selinc:sel-411l_firmware:r128-v0:*:*:*:*:*:*:*
selincsel-411l_firmwarer129-v0cpe:2.3:o:selinc:sel-411l_firmware:r129-v0:*:*:*:*:*:*:*
selincsel-411l-cpe:2.3:h:selinc:sel-411l:-:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

20.5%

Related for NVD:CVE-2023-2265