CVE-2023-31161: Selinc Sel-3350 Firmware
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow an authenticated remote attacker to use internal resources, allowing a variety of potential effects. See SEL Service Bulletin dated 2022-11-15 for more details.
Affected products
- Selinc Sel-3350 Firmware: from r148-v0, before r150-v2 (fixed in r150-v2)
- Selinc Sel-3532 Firmware: from r143-v0, before r150-v2 (fixed in r150-v2)
- Selinc Sel-3555 Firmware: from r143-v0, before r150-v2 (fixed in r150-v2)
- Selinc Sel-3560e Firmware: from r144-v2, before r150-v2 (fixed in r150-v2)
- Selinc Sel-3560s Firmware: from r144-v2, before r150-v2 (fixed in r150-v2)
Published 2023-05-10. Last modified 2026-06-17.