ZeroHour
Product

PowerChute Serial Shutdown

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Schneider Electric PowerChute Serial Shutdown

CISA and Schneider Electric warn that PowerChute Serial Shutdown 1.5 and prior lack brute-force protection, allowing unauthorized account access via unlimited authentication attempts.

CVE-2026-13348 (CWE-307, CVSS 5.3) in Schneider Electric PowerChute Serial Shutdown versions 1.5 and prior lets attackers perform an arbitrary number of authentication attempts when redirect handling is disabled, gaining unauthorized access to user accounts. The UPS management software is deployed across commercial facilities, critical manufacturing, energy, and IT sectors worldwide. CISA advisory ICSA-26-260-07 recommends network isolation, VPN-protected remote access, and applying the vendor fix.

[Control systems] Schneider Electric security advisory (AV26-871)

Canada's Cyber Centre relayed Schneider Electric advisories for vulnerabilities in NetBotz 5-750/755 (5.5.2 and prior) and PowerChute Serial Shutdown (1.5 and prior).

The Canadian Centre for Cyber Security issued control-systems advisory AV26-871 noting Schneider Electric products affected by vulnerabilities as of September 1, 2026. Affected products include NetBotz 5-750/755 versions 5.5.2 and prior, and PowerChute Serial Shutdown versions 1.5 and prior, the latter with an improper restriction of excessive authentication attempts flaw. Administrators are urged to review Schneider Electric's security notifications and apply the suggested mitigations and updates.

Canadian Centre for Cyber Security · 16d agoAdvisory

Related CVEs

  • Password brute-force flaw in Schneider Electric PowerChute Serial Shutdown
    Schneider Electric PowerChute Serial Shutdown, the management agent used with APC UPS devices, contains an improper restriction of excessive authentication attempts (CWE-307) that allows an unauthenticated attacker to make an arbitrary number of login attempts against a user account. The weakness manifests when redirect handling is disabled, in which case the software fails to enforce account lockout or rate limiting, enabling an online password brute-force attack. An attacker who succeeds gains unauthorized access to a PowerChute account; the CVSS 4.0 vector indicates low confidentiality impact with no direct integrity or availability impact, so the primary risk is unauthorized visibility into and use of a valid account. Any organization running the affected software is potentially affected, though installations whose web interface is reachable only from trusted internal networks face materially lower risk. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a 0.3% probability of exploitation within 30 days.
    · Schneider Electric PowerChute Serial Shutdownlarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.