PT-2023-5214 · Schweitzer Engineering Laboratories · Sel-5030 Acselerator Quickset

Gabriele Quagliarella

·

Published

2023-06-15

·

Updated

2023-09-05

·

CVE-2023-31171

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software versions through 7.1.3.0
Description The issue is related to an Improper Neutralization of Special Elements used in an SQL Command, also known as SQL Injection. This could allow an attacker to embed instructions that could be executed by an authorized device operator. The vulnerability is associated with the failure to protect the SQL query structure when processing DMX format files. Exploitation of the vulnerability may allow an attacker to execute arbitrary code using specially crafted malicious packets.
Recommendations For SEL-5030 acSELerator QuickSet Software versions through 7.1.3.0, refer to Instruction Manual Appendix A and Appendix E dated 20230615 for more details on mitigating the issue. As a temporary workaround, consider restricting access to the SQL command functionality until a patch is available. Additionally, avoid using the vulnerable import configuration function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-05822
CVE-2023-31171

Affected Products

Sel-5030 Acselerator Quickset