Vulnerabilities > Selinc > SEL 3505 3 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-10 CVE-2023-31160 Cross-site Scripting vulnerability in Selinc products
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-79
5.4
2023-05-10 CVE-2023-31162 Improper Input Validation vulnerability in Selinc products
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to arbitrarily alter the content of a configuration file. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-20
4.3
2023-05-10 CVE-2023-31163 Cross-site Scripting vulnerability in Selinc products
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-79
5.4
2023-05-10 CVE-2023-31164 Cross-site Scripting vulnerability in Selinc products
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-79
5.4
2023-05-10 CVE-2023-31165 Cross-site Scripting vulnerability in Selinc products
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-79
5.4
2023-05-10 CVE-2023-31166 Path Traversal vulnerability in Selinc products
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to create folders in arbitrary paths of the file system. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-22
4.3