Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator是美国Schweitzer Engineering Laboratories公司的一款免费分发的软件工具————网格配置器,可供工程师和技术人员快速创建、管理和部署 SEL 电力系统设备的设置。 Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator 存在安全漏洞,该漏洞源于权限配置不当。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Schweitzer Engineering Laboratories | SEL-5037 SEL Grid Configurator | 0 ~ 4.5.0.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-34392 | 8.2 HIGH | Missing Authentication for Critical Function |
| CVE-2023-31173 | 7.7 HIGH | Use of Hard-coded Credentials |
| CVE-2023-34391 | 7.4 HIGH | Insecure Inherited Permissions |
| CVE-2023-31174 | 7.4 HIGH | Cross-Site Request Forgery (CSRF) |
| CVE-2023-31172 | 5.9 MEDIUM | Incomplete Filtering of Special Elements |
| CVE-2023-31171 | 5.9 MEDIUM | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2023-31170 | 5.9 MEDIUM | Inclusion of Functionality from Untrusted Control Sphere |
| CVE-2023-31168 | 5.5 MEDIUM | Inclusion of Functionality from Untrusted Control Sphere |
| CVE-2023-31167 | 5.0 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2023-31169 | 4.8 MEDIUM | Improper Handling of Unicode Encoding |
No comments yet