CVE-2017-7928: Selinc Sel-3620 Firmware

Critical severity, CVSS 10.0. EPSS: 2.3% chance of exploitation in the next 30 days.

An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R204, R204-V1. The device does not properly enforce access control while configured for NAT port forwarding, which may allow for unauthorized communications to downstream devices.

Affected products

  • Selinc Sel-3620 Firmware: version r202 only; version r203 only; version r203-v only; version r203-v1 only; version r204 only; version r204-v1 only
  • Selinc Sel-3622 Firmware: version r202 only; version r203 only; version r203-v only; version r203-v1 only; version r204 only; version r204-v1 only

Published 2017-08-07. Last modified 2026-06-17.