CVE-2017-7928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
07/08/2017
Last modified:
20/04/2025

Description

An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R204, R204-V1. The device does not properly enforce access control while configured for NAT port forwarding, which may allow for unauthorized communications to downstream devices.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:selinc:sel-3620_firmware:r202:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3620_firmware:r203:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3620_firmware:r203-v:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3620_firmware:r203-v1:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3620_firmware:r204:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3620_firmware:r204-v1:*:*:*:*:*:*:*
cpe:2.3:h:selinc:sel-3620:-:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3622_firmware:r202:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3622_firmware:r203:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3622_firmware:r203-v:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3622_firmware:r203-v1:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3622_firmware:r204:*:*:*:*:*:*:*
cpe:2.3:o:selinc:sel-3622_firmware:r204-v1:*:*:*:*:*:*:*
cpe:2.3:h:selinc:sel-3622:-:*:*:*:*:*:*:*