Schweitzer Engineering Laboratories Real Time Automation Controller(SEL RTAC)是美国Schweitzer Engineering Laboratories公司的一个功能强大的多功能自动化平台。 Schweitzer Engineering Laboratories Real Time Automation Controller存在安全漏洞,该漏洞源于Web 界面中的存在不当输入验证,远程攻击者利用该漏洞可以执行任意更改配置文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Schweitzer Engineering Laboratories | SEL-3505 | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-3505-3 | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-3530 | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-3530-4 | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-3532 | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-3555 | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-3560S | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-3560E | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-2241 RTAC module | R149-V0 ~ R150-V2 | - |
|
| Schweitzer Engineering Laboratories | SEL-3350 | R149-V0 ~ R150-V2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-31148 | 9.1 CRITICAL | Improper Input Validation in Web Interface |
| CVE-2023-31149 | 9.1 CRITICAL | Improper Input Validation in Web Interface |
| CVE-2023-31150 | 8.0 HIGH | Storing Passwords in a Recoverable Format |
| CVE-2023-2310 | 6.8 MEDIUM | Channel Accessible by Non-Endpoint |
| CVE-2023-31161 | 5.9 MEDIUM | Improper Input Validation in Web Interface |
| CVE-2023-31151 | 4.7 MEDIUM | Improper Certificate Validation |
| CVE-2023-31156 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31153 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31154 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31155 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31157 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31158 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31159 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31160 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31163 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31164 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31165 | 4.3 MEDIUM | Improper Neutralization of Input During Web Page Generation |
| CVE-2023-31166 | 4.1 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory |
| CVE-2023-31152 | 4.0 MEDIUM | Authentication Bypass Using an Alternate Path or Channel |
No comments yet