CVE-2023-31177: Selinc Sel-451 Firmware

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An Improper Neutralization of Input During Web Page Generation  ('Cross-site Scripting') in the Schweitzer Engineering Laboratories SEL-451 could allow an attacker to craft a link that could execute arbitrary code on a victim's system. See product Instruction Manual Appendix A dated 20230830 for more details.

Affected products

  • Selinc Sel-451 Firmware: from r315-v0, before r315-v4 (fixed in r315-v4); from r316-v0, before r316-v4 (fixed in r316-v4); from r317-v0, before r317-v4 (fixed in r317-v4); from r318-v0, before r318-v5 (fixed in r318-v5); from r320-v0, before r320-v3 (fixed in r320-v3); from r321-v0, before r321-v3 (fixed in r321-v3); …

Published 2023-11-30. Last modified 2026-06-17.