Cross-Site Request Forgery (CSRF)
CVE-2023-31174

7.4HIGH

Key Information:

Vendor
CVE Published:
31 August 2023

What is CVE-2023-31174?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the SEL Grid Configurator by Schweitzer Engineering Laboratories. This vulnerability could potentially allow an attacker to embed malicious instructions, which may be executed by an authorized device operator, leading to unauthorized actions within the system. Users of the SEL-5037 SEL Grid Configurator are advised to upgrade to version 4.5.0.20 or later to mitigate this risk. For detailed guidance, refer to the Instruction Manual Appendix A and Appendix E dated 20230615.

Affected Version(s)

SEL-5037 SEL Grid Configurator Windows 0 < 4.5.0.20

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Palanca of Nozomi Networks
.