VYPR
Vendor

Schweitzer Engineering Laboratories, Inc.

Products
34
CVEs
50
Across products
153
Status
Private

Products

34
View all 34 products →

Recent CVEs

50
View all 50 CVEs →
  • CVE-2018-10600CriJul 24, 2018
    risk 0.64cvss 9.8epss 0.02

    SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieval of arbitrary data, arbitrary code execution (in certain situations on specific platforms), and denial of service attacks.

  • CVE-2023-31149CriMay 10, 2023
    risk 0.59cvss 9.1epss 0.01

    An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See SEL Service Bulletin dated 2022-11-15 for more details. …

  • CVE-2023-31148CriMay 10, 2023
    risk 0.59cvss 9.1epss 0.01

    An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See SEL Service Bulletin dated 2022-11-15 for more details.

  • CVE-2023-31175HigAug 31, 2023
    risk 0.57cvss 8.8epss 0.00

    An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run system commands with the highest level privilege on the system. See Instruction Manual Appendix A and Appendix E…

  • CVE-2018-10604HigJul 24, 2018
    risk 0.57cvss 8.8epss 0.02

    SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of privilege and/or malicious code execution.

  • CVE-2023-34392HigAug 31, 2023
    risk 0.53cvss 8.2epss 0.00

    A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator. See Instruction Manual Appendix A…

  • CVE-2023-31150HigMay 10, 2023
    risk 0.52cvss 8.0epss 0.00

    A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more…

  • CVE-2018-10608HigJul 24, 2018
    risk 0.52cvss 7.5epss 0.08

    SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization. Restart of the application is required.

  • CVE-2023-31173HigAug 31, 2023
    risk 0.50cvss 7.7epss 0.00

    Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid…

  • CVE-2023-31176HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated remote attacker to brute-force session tokens and bypass authentication.  See product Instruction Manual Appendix A dated 20230830 for more details.

  • CVE-2025-46737HigMay 12, 2025
    risk 0.48cvss 7.4epss 0.00

    SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes an API which is not properly configured to reject requests from unexpected sources.

  • CVE-2023-34391HigAug 31, 2023
    risk 0.48cvss 7.4epss 0.00

    Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230522 for more…

  • CVE-2023-31174HigAug 31, 2023
    risk 0.48cvss 7.4epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix…

  • CVE-2023-2310MedMay 10, 2023
    risk 0.44cvss 6.8epss 0.01

    A Channel Accessible by Non-Endpoint vulnerability in the Schweitzer Engineering Laboratories SEL Real-Time Automation Controller (RTAC) could allow a remote attacker to perform a man-in-the-middle (MiTM) that could result in denial of service. See the ACSELERATOR RTAC SEL-5033…

  • CVE-2025-46738MedMay 12, 2025
    risk 0.43cvss 6.6epss 0.00

    An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code.

  • CVE-2024-2103MedApr 4, 2024
    risk 0.42cvss 6.5epss 0.00

    Inclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the following Schweitzer Engineering Laboratories relays could allow the relay to behave unpredictably: SEL-700BT Motor Bus Transfer Relay, SEL-700G Generator Protection…

  • CVE-2023-34388MedNov 30, 2023
    risk 0.42cvss 6.5epss 0.01

    An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instruction Manual Appendix A dated 20230830 for…

  • CVE-2023-31172MedAug 31, 2023
    risk 0.38cvss 5.9epss 0.00

    An Incomplete Filtering of Special Elements vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual…

  • CVE-2023-31171MedAug 31, 2023
    risk 0.38cvss 5.9epss 0.00

    An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device…

  • CVE-2023-31170MedAug 31, 2023
    risk 0.38cvss 5.9epss 0.00

    An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction…