// For flags

CVE-2017-7928

 

Severity Score

10.0
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R204, R204-V1. The device does not properly enforce access control while configured for NAT port forwarding, which may allow for unauthorized communications to downstream devices.

Se ha descubierto un problema de control de acceso incorrecto en Schweitzer Engineering Laboratories (SEL) SEL-3620 y SEL-3622 Security Gateway Versiones R202 y, R203, R203-V1, R203-V2 y, R204, R204-V1. El dispositivo no aplica correctamente controles de acceso al estar configurado para el reenvío de puertos NAT, lo que podría permitir que se realizasen comunicaciones no autorizadas a dispositivos de bajada.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-04-18 CVE Reserved
  • 2017-08-07 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Selinc
Search vendor "Selinc"
Sel-3620 Firmware
Search vendor "Selinc" for product "Sel-3620 Firmware"
r202
Search vendor "Selinc" for product "Sel-3620 Firmware" and version "r202"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3620
Search vendor "Selinc" for product "Sel-3620"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3620 Firmware
Search vendor "Selinc" for product "Sel-3620 Firmware"
r203
Search vendor "Selinc" for product "Sel-3620 Firmware" and version "r203"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3620
Search vendor "Selinc" for product "Sel-3620"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3620 Firmware
Search vendor "Selinc" for product "Sel-3620 Firmware"
r203-v
Search vendor "Selinc" for product "Sel-3620 Firmware" and version "r203-v"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3620
Search vendor "Selinc" for product "Sel-3620"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3620 Firmware
Search vendor "Selinc" for product "Sel-3620 Firmware"
r203-v1
Search vendor "Selinc" for product "Sel-3620 Firmware" and version "r203-v1"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3620
Search vendor "Selinc" for product "Sel-3620"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3620 Firmware
Search vendor "Selinc" for product "Sel-3620 Firmware"
r204
Search vendor "Selinc" for product "Sel-3620 Firmware" and version "r204"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3620
Search vendor "Selinc" for product "Sel-3620"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3620 Firmware
Search vendor "Selinc" for product "Sel-3620 Firmware"
r204-v1
Search vendor "Selinc" for product "Sel-3620 Firmware" and version "r204-v1"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3620
Search vendor "Selinc" for product "Sel-3620"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3622 Firmware
Search vendor "Selinc" for product "Sel-3622 Firmware"
r202
Search vendor "Selinc" for product "Sel-3622 Firmware" and version "r202"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3622
Search vendor "Selinc" for product "Sel-3622"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3622 Firmware
Search vendor "Selinc" for product "Sel-3622 Firmware"
r203
Search vendor "Selinc" for product "Sel-3622 Firmware" and version "r203"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3622
Search vendor "Selinc" for product "Sel-3622"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3622 Firmware
Search vendor "Selinc" for product "Sel-3622 Firmware"
r203-v
Search vendor "Selinc" for product "Sel-3622 Firmware" and version "r203-v"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3622
Search vendor "Selinc" for product "Sel-3622"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3622 Firmware
Search vendor "Selinc" for product "Sel-3622 Firmware"
r203-v1
Search vendor "Selinc" for product "Sel-3622 Firmware" and version "r203-v1"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3622
Search vendor "Selinc" for product "Sel-3622"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3622 Firmware
Search vendor "Selinc" for product "Sel-3622 Firmware"
r204
Search vendor "Selinc" for product "Sel-3622 Firmware" and version "r204"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3622
Search vendor "Selinc" for product "Sel-3622"
--
Safe
Selinc
Search vendor "Selinc"
Sel-3622 Firmware
Search vendor "Selinc" for product "Sel-3622 Firmware"
r204-v1
Search vendor "Selinc" for product "Sel-3622 Firmware" and version "r204-v1"
-
Affected
in Selinc
Search vendor "Selinc"
Sel-3622
Search vendor "Selinc" for product "Sel-3622"
--
Safe