Schweitzer Engineering Laboratories Blueframe Software Session Management Vulnerability

Vulnerability

A vulnerability exists in the session management of Schweitzer Engineering Laboratories (SEL) Blueframe software, specifically in the Blueframe OS version 1.12.0 and in the Blueframe Application Suite version 1.1.0.0. This vulnerability allows an authenticated user's token to be used by another source after the user has logged out, but before the token has expired. This issue could potentially be exploited to gain unauthorized access or perform actions on behalf of the user.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed with the privileges of the logged-out user, potentially allowing access to sensitive information or the ability to modify data or settings.

Remediation

Users can update to the latest version of the SEL Blueframe software, which includes the session management fix. For detailed instructions on updating, refer to the SEL Blueframe software release notes.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.