An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated remote attacker to brute-force session tokens and bypass authentication.
See product Instruction Manual Appendix A dated 20230830 for more details.
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sel-451_firmware | Selinc | r315-v0 (including) | r315-v4 (excluding) |
Sel-451_firmware | Selinc | r316-v0 (including) | r316-v4 (excluding) |
Sel-451_firmware | Selinc | r317-v0 (including) | r317-v4 (excluding) |
Sel-451_firmware | Selinc | r318-v0 (including) | r318-v5 (excluding) |
Sel-451_firmware | Selinc | r320-v0 (including) | r320-v3 (excluding) |
Sel-451_firmware | Selinc | r321-v0 (including) | r321-v3 (excluding) |
Sel-451_firmware | Selinc | r322-v0 (including) | r322-v3 (excluding) |
Sel-451_firmware | Selinc | r323-v0 (including) | r323-v5 (excluding) |
Sel-451_firmware | Selinc | r324-v0 (including) | r324-v4 (excluding) |
Sel-451_firmware | Selinc | r325-v0 (including) | r325-v3 (excluding) |
Sel-451_firmware | Selinc | r326-v0 (including) | r326-v0 (including) |
Sel-451_firmware | Selinc | r327-v0 (including) | r327-v0 (including) |