CVE-2023-31150
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more details.
Scoring
- Severity
- HIGH
- CVSS base score
- 8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.14%
- CWE
- CWE-257
- Published
- 2023-05-10
- Last modified
- 2026-03-13
Affected products
- Schweitzer Engineering Laboratories SEL-3505
- Schweitzer Engineering Laboratories SEL-3505-3
- Schweitzer Engineering Laboratories SEL-3530
- Schweitzer Engineering Laboratories SEL-3530-4
- Schweitzer Engineering Laboratories SEL-3532
- Schweitzer Engineering Laboratories SEL-3555
- Schweitzer Engineering Laboratories SEL-3560S
- Schweitzer Engineering Laboratories SEL-3560E
Weakness type
Related vulnerabilities
- CVE-2026-20128 — Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
- CVE-2025-8904 — Privilege escalation issue in Amazon EMR Secret Agent component
- CVE-2025-6996 — Improper Encryption in Ivanti Endpoint Manager
- CVE-2025-6995 — Improper Encryption in Ivanti Endpoint Manager
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2019-3736 — Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM
- CVE-2022-34838 — ABB Ability TM Operations Data Management Zenon Zenon Log Server file access control
- CVE-2022-32519 — A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE