CVE-2023-31170

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 31, 2023
Updated: Sep 5, 2023
CWE ID 829

Summary

CVE-2023-31170 is a vulnerability affecting Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software. An attacker can exploit this Inclusion of Functionality from Untrusted Control Sphere flaw to embed instructions that authorized device operators can execute. The vulnerability, detailed in the software's Appendix A and E from the 20230615 manual, can be found in versions of the software through 7.1.3.0. This issue poses a potential risk to device security, making it crucial for users to update their software as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share