Lucene search

K
nvd[email protected]NVD:CVE-2023-31148
HistoryMay 10, 2023 - 8:15 p.m.

CVE-2023-31148

2023-05-1020:15:09
CWE-20
web.nvd.nist.gov
9
input validation
sel rtac
remote code execution
authentication
cwe-20
cwe-78
cve-2023-31148
schweitzer engineering laboratories

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

69.0%

An Improper Input Validation vulnerability

in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code.
See SEL Service Bulletin dated 2022-11-15 for more details.

Affected configurations

Nvd
Node
selincsel-2241_rtac_moduleMatch-
AND
selincsel-2241_rtac_module_firmwareRanger132-v0r150-v2
Node
selincsel-3350Match-
AND
selincsel-3350_firmwareRanger148-v0r150-v2
Node
selincsel-3505_firmwareRanger132-v0r150-v2
AND
selincsel-3505Match-
Node
selincsel-3505-3_firmwareRanger132-v0r150-v2
AND
selincsel-3505-3Match-
Node
selincsel-3530Match-
AND
selincsel-3530_firmwareRanger132-v0r150-v2
Node
selincsel-3530-4Match-
AND
selincsel-3530-4_firmwareRanger132-v0r150-v2
Node
selincsel-3532Match-
AND
selincsel-3532_firmwareRanger132-v0r150-v2
Node
selincsel-3555Match-
AND
selincsel-3555_firmwareRanger134-v0r150-v2
Node
selincsel-3560eMatch-
AND
selincsel-3560e_firmwareRanger144-v2r150-v2
Node
selincsel-3560sMatch-
AND
selincsel-3560s_firmwareRanger144-v2r150-v2
VendorProductVersionCPE
selincsel-2241_rtac_module-cpe:2.3:h:selinc:sel-2241_rtac_module:-:*:*:*:*:*:*:*
selincsel-2241_rtac_module_firmware*cpe:2.3:o:selinc:sel-2241_rtac_module_firmware:*:*:*:*:*:*:*:*
selincsel-3350-cpe:2.3:h:selinc:sel-3350:-:*:*:*:*:*:*:*
selincsel-3350_firmware*cpe:2.3:o:selinc:sel-3350_firmware:*:*:*:*:*:*:*:*
selincsel-3505_firmware*cpe:2.3:o:selinc:sel-3505_firmware:*:*:*:*:*:*:*:*
selincsel-3505-cpe:2.3:h:selinc:sel-3505:-:*:*:*:*:*:*:*
selincsel-3505-3_firmware*cpe:2.3:o:selinc:sel-3505-3_firmware:*:*:*:*:*:*:*:*
selincsel-3505-3-cpe:2.3:h:selinc:sel-3505-3:-:*:*:*:*:*:*:*
selincsel-3530-cpe:2.3:h:selinc:sel-3530:-:*:*:*:*:*:*:*
selincsel-3530_firmware*cpe:2.3:o:selinc:sel-3530_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

69.0%

Related for NVD:CVE-2023-31148