Security restrictions bypass in Schweitzer Engineering Laboratories SEL-3620 and SEL-3622

Published: 2017-07-12 13:34:00
Severity Low
Patch available YES
Number of vulnerabilities 1
CVSSv2 4.7 (AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
CVSSv3 6.1 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE ID CVE-2017-7928
CWE ID CWE-284
Exploitation vector Network
Public exploit Not available
Vulnerable software SEL-3622
SEL-3620
Vulnerable software versions SEL-3622 R204-V1
SEL-3622 R204
SEL-3622 R203-V2
Show more
SEL-3620 R204-V1
SEL-3620 R204
SEL-3620 R203-V2
Show more
Vendor URL Schweitzer Engineering Laboratories, Inc.
Advisory type Public

Security Advisory

1) Security restrictions bypass

Description

The vulnerability allows a remote attacker to bypass security restrictions.

The weakness exists due to improper enforcing of access control while configured for NAT port forwarding. A remote attacker can use unauthorized communications to downstream devices.

Remediation

Install update from vendor's website.

External links

https://ics-cert.us-cert.gov/advisories/ICSA-17-192-06

Back to List