AnĀ Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering Laboratories SEL-411L could allow an unauthenticated attacker to perform clickjacking based attacks against an authenticated and authorized user.
See product Instruction Manual Appendix A dated 20230830 for more details.
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sel-411l_firmware | Selinc | r118-v0 (including) | r118-v4 (excluding) |
| Sel-411l_firmware | Selinc | r119-v0 (including) | r119-v5 (excluding) |
| Sel-411l_firmware | Selinc | r120-v0 (including) | r120-v6 (excluding) |
| Sel-411l_firmware | Selinc | r121-v0 (including) | r121-v3 (excluding) |
| Sel-411l_firmware | Selinc | r122-v0 (including) | r122-v3 (excluding) |
| Sel-411l_firmware | Selinc | r123-v0 (including) | r123-v3 (excluding) |
| Sel-411l_firmware | Selinc | r124-v0 (including) | r124-v3 (excluding) |
| Sel-411l_firmware | Selinc | r125-v0 (including) | r125-v3 (excluding) |
| Sel-411l_firmware | Selinc | r126-v0 (including) | r126-v4 (excluding) |
| Sel-411l_firmware | Selinc | r127-v0 (including) | r127-v2 (excluding) |
| Sel-411l_firmware | Selinc | r128-v0 (including) | r128-v0 (including) |
| Sel-411l_firmware | Selinc | r129-v0 (including) | r129-v0 (including) |