Vulnerabilities > Selinc

DATE CVE VULNERABILITY TITLE RISK
2018-07-24 CVE-2018-10608 Resource Exhaustion vulnerability in Selinc Acselerator Architect 2.2.24.0
SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization.
network
low complexity
selinc CWE-400
7.8
2018-07-24 CVE-2018-10604 Incorrect Default Permissions vulnerability in Selinc SEL Compass 3.0.5.1
SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of privilege and/or malicious code execution.
network
low complexity
selinc CWE-276
6.5
2018-07-24 CVE-2018-10600 XXE vulnerability in Selinc Acselerator Architect 2.2.24.0
SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieval of arbitrary data, arbitrary code execution (in certain situations on specific platforms), and denial of service attacks.
network
low complexity
selinc CWE-611
7.5
2017-08-07 CVE-2017-7928 Unspecified vulnerability in Selinc Sel-3620 Firmware and Sel-3622 Firmware
An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R204, R204-V1.
network
low complexity
selinc
7.5
2013-08-09 CVE-2013-2798 Improper Input Validation vulnerability in Selinc products
Schweitzer Engineering Laboratories (SEL) SEL-2241, SEL-3505, and SEL-3530 RTAC master devices allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.
local
selinc CWE-20
4.7
2013-08-09 CVE-2013-2792 Improper Input Validation vulnerability in Selinc products
Schweitzer Engineering Laboratories (SEL) SEL-2241, SEL-3505, and SEL-3530 RTAC master devices allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.
network
selinc CWE-20
7.1
2013-03-21 CVE-2013-0665 Permissions, Privileges, and Access Controls vulnerability in Selinc Acselerator Quickset
Schweitzer Engineering Laboratories (SEL) AcSELerator QuickSet before 5.12.0.1 uses weak permissions for its Program Files directory, which allows local users to replace executable files, and consequently gain privileges, via standard filesystem operations.
local
high complexity
selinc CWE-264
6.2