Insufficient entropy vulnerability could lead to authentication bypass
CVE-2023-31176
7.5HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 30 November 2023
What is CVE-2023-31176?
The SEL-451 by Schweitzer Engineering Laboratories is affected by an Insufficient Entropy vulnerability, which permits unauthenticated remote attackers to exploit weak session tokens. By leveraging this flaw, attackers can perform brute-force attacks to bypass authentication mechanisms, potentially leading to unauthorized access. Additional insights can be found in the product's Instruction Manual Appendix A dated 20230830.
Affected Version(s)
SEL-451 R315-V0
SEL-451 R316-V0
SEL-451 R317-V0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrea Palanca and Gabriele Quagliarella of Nozomi Networks