Vulnerabilidades en Schweitzer Engineering Laboratories

60 resultados
Análisis Vexday

Com 60 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Schweitzer Engineering Laboratories situa-se abaixo da média geral do catálogo, o que sugere uma superfície de ataque com menor pressão imediata de ameaças oportunistas. Das vulnerabilidades registradas, 3 são de severidade crítica e nenhuma conta com prova de conceito pública disponível, reduzindo o risco de exploração massiva no curto prazo. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), indicando que vetores de injeção em interfaces web merecem atenção nos ciclos de revisão de código e hardening. A CVE mais perigosa ativa no momento, CVE-2023-31148, apresenta escore EPSS de 0,0109, reforçando que, embora o risco operacional seja atualmente contido, o monitoramento contínuo permanece recomendado dado o contexto crítico dos ambientes de automação onde esses dispositivos tipicamente operam.

CVE-2023-31148CRITICALImproper Input Validation in Web InterfaceEPSS 1.1%CVE-2023-31149CRITICALImproper Input Validation in Web InterfaceEPSS 1.1%CVE-2023-31176HIGHInsufficient entropy vulnerability could lead to authentication bypassEPSS 0.9%CVE-2023-34388MEDIUMImproper authentication could lead to session hijackingEPSS 0.9%CVE-2023-34389MEDIUMAllocation of resources without limits could lead to denial of serviceEPSS 0.7%CVE-2023-34390MEDIUM Improper input validation could lead to denial of serviceEPSS 0.7%CVE-2023-31166MEDIUMImproper Limitation of a Pathname to a Restricted DirectoryEPSS 0.6%CVE-2023-31161MEDIUMImproper Input Validation in Web InterfaceEPSS 0.5%CVE-2023-2310MEDIUMChannel Accessible by Non-EndpointEPSS 0.5%CVE-2023-31177MEDIUMImproper neutralizataion of input could lead to execution of arbitrary codeEPSS 0.5%CVE-2023-31162MEDIUMImproper Input Validation in Web InterfaceEPSS 0.5%CVE-2023-31150HIGHStoring Passwords in a Recoverable FormatEPSS 0.5%CVE-2024-2103MEDIUMInclusion of Undocumented FeaturesEPSS 0.5%CVE-2023-34392HIGHMissing Authentication for Critical FunctionEPSS 0.5%CVE-2023-31160MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31156MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31155MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31159MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31158MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31165MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%