Lucene search

K

Sel-451 Firmware Security Vulnerabilities

cve
cve

CVE-2023-31176

An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated remote attacker to brute-force session tokens and bypass authentication. See product Instruction Manual Appendix A dated 20230830 for more details.

9.8CVSS

9.4AI Score

0.001EPSS

2023-11-30 05:15 PM
14
cve
cve

CVE-2023-31177

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the Schweitzer Engineering Laboratories SEL-451 could allow an attacker to craft a link that could execute arbitrary code on a victim's system. See product Instruction Manual Appendix A dated 20230830 for mor...

6.1CVSS

6.6AI Score

0.001EPSS

2023-11-30 05:15 PM
16
cve
cve

CVE-2023-34388

An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instruction Manual Appendix A dated 20230830 for more details.

9.8CVSS

9.4AI Score

0.001EPSS

2023-11-30 05:15 PM
16
cve
cve

CVE-2023-34389

An allocation of resources without limits or throttling vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to make the system unavailable for an indefinite amount of time. See product Instruction Manual Appendix A dated 20230830 for more det...

6.5CVSS

6.2AI Score

0.001EPSS

2023-11-30 05:15 PM
13
cve
cve

CVE-2023-34390

An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to create a denial of service against the system and locking out services. See product Instruction Manual Appendix A dated 20230830 for more details.

6.5CVSS

6.2AI Score

0.001EPSS

2023-11-30 05:15 PM
13