Selinc develops industrial control and power systems protection equipment, with a concentrated portfolio centered on protective relay and automation devices such as the SEL-3505 and SEL-3530 product lines that are widely deployed in critical infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the safety-critical nature of grid and substation automation where reliability and availability demands are high. The exposure recurs through input-validation and authentication weaknesses characteristic of networked embedded systems, including improper neutralization of web-facing inputs and insufficient credential handling in devices that may have extended operational lifespans. Defenders should prioritize patches for this vendor's releases given the industrial control context and the potential for cascading impact in power distribution networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Selinc over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10608HIGH SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of servic | Jul 24, 2018 | 7.5 | 37 | NO | YES |
CVE-2018-10600CRITICAL SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieval of arbitrary data, arbitrary | Jul 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2023-31176CRITICAL An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated remote attacker to brute-force session tokens and bypass aut | Nov 30, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-7928CRITICAL An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R | Aug 7, 2017 | 10.0 | 30 | NO | NO |
CVE-2023-31175CRITICAL
An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run system commands wit | Aug 31, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-31161HIGH An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow an authenticated remote a | May 10, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-31149HIGH
An Improper Input Validation vulnerability
in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated | May 10, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-31148HIGH An Improper Input Validation vulnerability
in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated | May 10, 2023 | 8.8 | 26 | NO | NO |
CVE-2018-10604HIGH SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installatio | Jul 24, 2018 | 8.8 | 26 | NO | NO |
CVE-2023-34392HIGH
A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary com | Aug 31, 2023 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Selinc.
Media articles that mention a CVE ID that affects a product developed by Selinc — matched by CVE ID, not by vendor name.