Cyber Resilience

CVE-2023-31150

Selinc Sel-2241 Rtac Module Firmware r122-v0 – r150-v2

Published
10 May 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 8.0
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0047 39th percentile
Risk Priority 54 floored blend · peak EPSS

Summary

CVE-2023-31150 is a high-severity Storing Passwords in a Recoverable Format (CWE-257) vulnerability in Selinc Sel-2241 Rtac Module Firmware. Its CVSS base score is 8.0 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Unsecured Credentials (T1552); ranked at the 39th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more details.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
T1552.006 Group Policy Preferences Credential Access
Adversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP).
T1552.001 Credentials In Files Credential Access
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
T1552.004 Private Keys Credential Access
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
T1552.002 Credentials in Registry Credential Access
Adversaries may search the Registry on compromised systems for insecurely stored credentials.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-31152Same product: Selinc Sel-2241 Rtac Module
CVE-2023-31160Same product: Selinc Sel-2241 Rtac Module
CVE-2023-31156Same product: Selinc Sel-2241 Rtac Module
CVE-2023-31149Same product: Selinc Sel-2241 Rtac Module
CVE-2023-31158Same product: Selinc Sel-2241 Rtac Module
CVE-2023-31163Same product: Selinc Sel-2241 Rtac Module
CVE-2023-31148Same product: Selinc Sel-2241 Rtac Module
CVE-2023-31151Same product: Selinc Sel-2241 Rtac Module
CVE-2023-31153Same product: Selinc Sel-2241 Rtac Module
CVE-2023-2310Same product: Selinc Sel-2241 Rtac Module

Affected Assets

selinc
sel-2241 rtac module firmware
r122-v0 — r150-v2
selinc
sel-3350 firmware
r148-v0 — r150-v2
selinc
sel-3505 firmware
r122-v0 — r150-v2
selinc
sel-3505-3 firmware
r132-v0 — r150-v2
selinc
sel-3530 firmware
r122-v0 — r150-v2
selinc
sel-3530-4 firmware
r122-v0 — r150-v2
selinc
sel-3532 firmware
r132-v0 — r150-v2
selinc
sel-3555 firmware
r134-v0 — r150-v2
selinc
sel-3560e firmware
r144-v2 — r150-v2
selinc
sel-3560s firmware
r144-v2 — r150-v2

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 3 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V11.4.2
  • V11.4.4

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-922

Tracking information locations and access supports secure storage practices instead of insecure ones.

addresses: CWE-922

Establishing an alternate site with equivalent protections directly mitigates insecure storage of sensitive backup information.

addresses: CWE-922

Requiring protection of backup information directly addresses insecure storage of sensitive data in backups.

addresses: CWE-922

Policy explicitly addresses insecure storage of CUI on external systems, requiring compliant handling and protections.

addresses: CWE-922

Proper categorization drives selection of storage controls that keep sensitive information from being stored insecurely.

addresses: CWE-922

The control explicitly requires secure storage mechanisms for sensitive information, closing the insecure-storage weakness class.

addresses: CWE-922

Storing information as fragments on distinct components is an architectural control that avoids insecure single-location storage of the complete sensitive data set.

addresses: CWE-922

OPSEC requirements improve handling and storage practices for sensitive supply-chain information.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.AA-05 mostly match
prevents

Enforces least-privilege permissions and authorization reviews that limit read/write access to stored sensitive data.

PR.DS-01 mostly match
prevents

Protecting data-at-rest with cryptographic hashes directly prevents recoverable password storage.

PR.PS-06 partial match
prevents

Secure SDLC practices include requirements for non-recoverable password storage.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

degrades

Directly requires secure handling and protection of authentication information, preventing storage in recoverable formats.

degrades

Mandates secure authentication mechanisms that preclude recoverable password storage.

degrades

Requires proper use of cryptography, which can mitigate recoverable storage if applied correctly to passwords.

prevents

Secure SDLC includes requirements that reduce the likelihood of introducing recoverable password storage.

prevents

Secure coding practices can prevent developers from implementing recoverable password storage.

mitigates

Secure reuse and disposal procedures, including cryptographic wiping and physical destruction, stop the insecure storage of sensitive data on media that may later be accessed by unauthorized actors.

Hardening callouts derived

Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).

Windows Server 2016 (2 rules)
  • V-224973 The Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions. prevents CWE-922
  • V-224974 Domain-created Active Directory Organizational Unit (OU) objects must have proper access control permissions. prevents CWE-922
Windows Server 2019 (1 rule)
  • V-205743 Windows Server 2019 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions. prevents CWE-922

References