Medium severity4.1NVD Advisory· Published May 10, 2023· Updated Jun 17, 2026
CVE-2023-31166
CVE-2023-31166
Description
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to create folders in arbitrary paths of the file system.
See SEL Service Bulletin dated 2022-11-15 for more details.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- cpe:2.3:o:selinc:sel-2241_rtac_module_firmware:*:*:*:*:*:*:*:*Range: >=r126-v0,<r150-v2
- cpe:2.3:o:selinc:sel-3505-3_firmware:*:*:*:*:*:*:*:*Range: >=r132-v0,<r150-v2
- cpe:2.3:o:selinc:sel-3530-4_firmware:*:*:*:*:*:*:*:*Range: >=r126-v0,<r150-v2
- cpe:2.3:o:selinc:sel-3560e_firmware:*:*:*:*:*:*:*:*Range: >=r144-v2,<r150-v2
- cpe:2.3:o:selinc:sel-3560s_firmware:*:*:*:*:*:*:*:*Range: >=r144-v2,<r150-v2
- Range: R126-V0
- Range: R134-V0
- Range: R144-V2
- Range: R126-V0
Patches
Vulnerability mechanics
References
2- selinc.com/support/security-notifications/external-reports/nvdVendor Advisory
- www.nozominetworks.com/blog/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.