Vulnerabilidades em Schweitzer Engineering Laboratories

60 resultados
Análise Vexday

Com 60 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Schweitzer Engineering Laboratories situa-se abaixo da média geral do catálogo, o que sugere uma superfície de ataque com menor pressão imediata de ameaças oportunistas. Das vulnerabilidades registradas, 3 são de severidade crítica e nenhuma conta com prova de conceito pública disponível, reduzindo o risco de exploração massiva no curto prazo. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), indicando que vetores de injeção em interfaces web merecem atenção nos ciclos de revisão de código e hardening. A CVE mais perigosa ativa no momento, CVE-2023-31148, apresenta escore EPSS de 0,0109, reforçando que, embora o risco operacional seja atualmente contido, o monitoramento contínuo permanece recomendado dado o contexto crítico dos ambientes de automação onde esses dispositivos tipicamente operam.

CVE-2023-31156MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31157MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31153MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31164MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31165MEDIUMImproper Neutralization of Input During Web Page GenerationEPSS 0.4%CVE-2023-31175HIGHExecution with Unnecessary PrivilegesEPSS 0.4%CVE-2023-2266MEDIUMImproper neutralization of input during web page generation could lead to cross-site scripting based attacksEPSS 0.4%CVE-2023-2267MEDIUMImproper input validation could lead to reflection injection attacksEPSS 0.4%CVE-2023-31168MEDIUM Inclusion of Functionality from Untrusted Control SphereEPSS 0.4%CVE-2023-2265MEDIUMImproper restriction of rendered UI layers or frames could lead to clickjacking attackEPSS 0.4%CVE-2023-31167MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.4%CVE-2025-48017CRITICALImproper Limitation of a Pathname to a Restricted DirectoryEPSS 0.4%CVE-2025-48014HIGHImproper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2023-31169MEDIUMImproper Handling of Unicode EncodingEPSS 0.4%CVE-2023-31152MEDIUMAuthentication Bypass Using an Alternate Path or ChannelEPSS 0.4%CVE-2023-31171MEDIUMImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')EPSS 0.3%CVE-2025-46739HIGHImproper Restriction of Excessive Authentication AttemptsEPSS 0.3%CVE-2023-31170MEDIUM Inclusion of Functionality from Untrusted Control SphereEPSS 0.3%CVE-2023-31172MEDIUMIncomplete Filtering of Special ElementsEPSS 0.3%CVE-2025-46740HIGHImproper Handling of Insufficient PermissionsEPSS 0.3%