Missing Authentication for Critical Function
CVE-2023-34392

8.2HIGH

Key Information:

Vendor
CVE Published:
31 August 2023

What is CVE-2023-34392?

The SEL-5037 Grid Configurator by Schweitzer Engineering Laboratories contains a vulnerability that allows an attacker to exploit missing authentication mechanisms to run arbitrary commands on devices managed by an authorized device operator. This can potentially lead to unauthorized access and manipulation of critical system functions. Users are advised to update to version 4.5.0.20 or later to mitigate this risk.

Affected Version(s)

SEL-5037 SEL Grid Configurator Windows 0 < 4.5.0.20

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Palanca and Gabriele Quagliarella of Nozomi Networks
.