CPE
medium
advisory
Authentication Bypass Vulnerability in Schneider Electric PowerChute Serial Shutdown
1 TTP 1 CVESchneider Electric PowerChute Serial Shutdown version 1.5 and prior contains an improper restriction of excessive authentication attempts vulnerability (CVE-2026-13348) that may allow unauthorized account access via brute-force.
PowerChute Serial Shutdown
industrial-control-system
authentication-bypass
cve
1t
1c
high
threat
Multiple Vulnerabilities in Schneider Electric PowerChute Serial Shutdown
5 TTPs 5 CVEsMultiple vulnerabilities, including CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, and CVE-2026-2401, in Schneider Electric PowerChute Serial Shutdown versions 1.4 and prior could allow attackers with adjacent network access and high privileges to overwrite critical system files via path traversal, forge or inject malicious log data, gain unauthorized account access through excessive authentication attempts, trigger denial-of-service conditions, or expose sensitive information.
exploited
PowerChute Serial Shutdown
ics
ot
vulnerability
path-traversal
crlf-injection
dos
log-tampering
critical-infrastructure
5t
5c