First published: Wed May 10 2023(Updated: )
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin dated 2022-11-15 for more details.
Credit: security@selinc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Selinc Sel-2241 RTAC Module Firmware | >=r113-v0<r150-v2 | |
Selinc Sel-2241 Rtac Module Firmware | ||
Selinc Sel-3350 Firmware | >=r148-v0<r150-v2 | |
Selinc Sel-3350 Firmware | ||
SEL-3505 Firmware | >=r119-v0<r150-v2 | |
SEL-3505 Firmware | ||
SEL-3505 Firmware | >=r132-v0<r150-v2 | |
SEL-3505 Firmware | ||
Selinc Sel-3530-4 | >=r100-v0<r150-v2 | |
Selinc Sel-3530 Firmware | ||
Selinc Sel-3530-4 | >=r108-v0<r150-v2 | |
SEL-3530-4 | ||
Selinc Sel-3532 | >=r132-v0<r150-v2 | |
Selinc Sel-3532 Firmware | ||
Selinc Sel-3555 Firmware | >=r134-v0<r150-v2 | |
Selinc Sel-3555 Firmware | ||
Selinc Sel-3560e Firmware | >=r144-v2<r150-v2 | |
Selinc Sel-3560e Firmware | ||
Selinc Sel-3560s | >=r144-v2<r150-v2 | |
Selinc SEL-3560S |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31160
The severity of CVE-2023-31160 is medium.
The Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface is affected by CVE-2023-31160.
CVE-2023-31160 allows a remote authenticated attacker to inject and execute arbitrary script code through the SEL RTAC Web Interface.
It is recommended to apply the latest security patches or updates provided by Schweitzer Engineering Laboratories to fix CVE-2023-31160.