SEL-5030
cpe:2.3:a:selinc:sel-5030_acselerator_quickset:*:*:*:*:*:*:*
- < 7.5.2.3
A vulnerability exists in the Circuit Provisioning and File Import applications from Schweitzer Engineering Laboratories due to improper limitations on file pathnames. This flaw allows for the unauthorized modification and uploading of files. The issue has been addressed by removing these applications in the latest software update.
Exploitation of this vulnerability could lead to unauthorized file modifications and uploads, potentially allowing for arbitrary code execution.
Users can update to the latest version of the affected software, where this vulnerability has been addressed by removing the Circuit Provisioning and File Import applications. Instructions for updating can be found in the SEL Software Release Notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.