CVE-2025-46737

HIGH

SEL-5037 Grid Configurator - SSRF

Title source: llm
STIX 2.1

Description

SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes an API which is not properly configured to reject requests from unexpected sources.

Scores

CVSS v3 7.4
EPSS 0.0008
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (1)
Schweitzer Engineering Laboratories/SEL-5037 Grid Configurator < 6.4.0.58
Published May 12, 2025
Tracked Since Feb 18, 2026