47 results (0.005 seconds)

CVSS: 6.4EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An Improper Input Validation vulnerability in Schweitzer Engineering Laboratories SEL-411L could allow an attacker to perform reflection attacks against an authorized and authenticated user. See product Instruction Manual Appendix A dated 20230830 for more details. Una vulnerabilidad de validación de entrada incorrecta en Schweitzer Engineering Laboratories SEL-411L podría permitir a un atacante realizar ataques de reflexión contra un usuario autorizado y autenticado. Consulte el Apéndice A del Manual de in... • https://selinc.com/support/security-notifications/external-reports • CWE-20: Improper Input Validation •

CVSS: 6.4EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An Improper neutralization of input during web page generation in the Schweitzer Engineering Laboratories SEL-411L could allow an attacker to generate cross-site scripting based attacks against an authorized and authenticated user. See product Instruction Manual Appendix A dated 20230830 for more details. Una neutralización inadecuada de la entrada durante la generación de una página web en Schweitzer Engineering Laboratories SEL-411L podría permitir a un atacante generar ataques basados en cross site scrip... • https://selinc.com/support/security-notifications/external-reports • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user. See product Instruction Manual Appendix A dated 20230830 for more details. Una restricción inadecuada de las capas o marcos de la interfaz de usuario renderizados en el SEL-411L de Schweitzer Engineering Laboratories podría permitir que un atacante no autenticado realice ataques ... • https://selinc.com/support/security-notifications/external-reports • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •

CVSS: 7.8EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An improper input validation vulnerability in the Schweitzer Engineering Laboratories SEL-411L could allow a malicious actor to manipulate authorized users to click on a link that could allow undesired behavior. See product Instruction Manual Appendix A dated 20230830 for more details. Una vulnerabilidad de validación de entrada incorrecta en Schweitzer Engineering Laboratories SEL-411L podría permitir que un actor malintencionado manipule a los usuarios autorizados para que hagan clic en un enlace que podr... • https://selinc.com/support/security-notifications/external-reports • CWE-20: Improper Input Validation •

CVSS: 6.8EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to create a denial of service against the system and locking out services. See product Instruction Manual Appendix A dated 20230830 for more details. Una vulnerabilidad de validación de entrada en Schweitzer Engineering Laboratories SEL-451 podría permitir que un atacante autenticado remoto cree una denegación de servicio contra el sistema y bloquee los servicios. Consulte el Apén... • https://selinc.com/support/security-notifications/external-reports • CWE-20: Improper Input Validation •

CVSS: 6.8EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An allocation of resources without limits or throttling vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to make the system unavailable for an indefinite amount of time. See product Instruction Manual Appendix A dated 20230830 for more details. Una asignación de recursos sin límites o vulnerabilidad de limitación en Schweitzer Engineering Laboratories SEL-451 podría permitir que un atacante autenticado remoto haga que el sistema no esté disponible ... • https://selinc.com/support/security-notifications/external-reports • CWE-770: Allocation of Resources Without Limits or Throttling •

CVSS: 10.0EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instruction Manual Appendix A dated 20230830 for more details. Una vulnerabilidad de autenticación incorrecta en Schweitzer Engineering Laboratories SEL-451 podría permitir que un atacante remoto no autenticado realice potencialmente un ataque de secuestro de sesión y omita la autentica... • https://selinc.com/support/security-notifications/external-reports • CWE-287: Improper Authentication •

CVSS: 6.4EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the Schweitzer Engineering Laboratories SEL-451 could allow an attacker to craft a link that could execute arbitrary code on a victim's system. See product Instruction Manual Appendix A dated 20230830 for more details. Una neutralización inadecuada de la entrada durante la generación de páginas web ("Cross-site Scripting") en Schweitzer Engineering Laboratories SEL-451 podría permitir a un atacante crear un enlace que... • https://selinc.com/support/security-notifications/external-reports • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 13EXPL: 0

30 Nov 2023 — An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated remote attacker to brute-force session tokens and bypass authentication. See product Instruction Manual Appendix A dated 20230830 for more details. Una vulnerabilidad de entropía insuficiente en Schweitzer Engineering Laboratories SEL-451 podría permitir que un atacante remoto no autenticado utilice tokens de sesión de fuerza bruta y eluda la autenticación. Consulte el Apéndice A del Manua... • https://selinc.com/support/security-notifications/external-reports • CWE-331: Insufficient Entropy •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

31 Aug 2023 — A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20. • https://selinc.com/support/security-notifications/external-reports • CWE-306: Missing Authentication for Critical Function •