CVE-2023-31160
Improper Neutralization of Input During Web Page Generation
In short
The SEL RTAC web interface fails to properly filter user input, allowing an authenticated attacker to inject malicious scripts that execute in other users' browsers. This can compromise sensitive control system data or actions.
Technical detail
CWE-79 Stored or Reflected XSS vulnerability in SEL RTAC web interface lacks input sanitization during page generation. Attack vector requires prior authentication; attacker can inject arbitrary JavaScript to be executed in victim's session, potentially leading to unauthorized commands or data theft in the industrial control environment.
Summary generated and translated by AI from the official description.
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code.
See SEL Service Bulletin dated 2022-11-15 for more details.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Affected products
Schweitzer Engineering Laboratories · SEL-2241 RTAC moduleSchweitzer Engineering Laboratories · SEL-3350Schweitzer Engineering Laboratories · SEL-3505Schweitzer Engineering Laboratories · SEL-3505-3Schweitzer Engineering Laboratories · SEL-3530Schweitzer Engineering Laboratories · SEL-3530-4Schweitzer Engineering Laboratories · SEL-3532Schweitzer Engineering Laboratories · SEL-3555Schweitzer Engineering Laboratories · SEL-3560ESchweitzer Engineering Laboratories · SEL-3560SWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →