{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/powerchute-serial-shutdown--1.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:schneider-electric:powerchute_serial_shutdown:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-13348"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PowerChute Serial Shutdown (\u003c= 1.5)"],"_cs_severities":["medium"],"_cs_tags":["industrial-control-system","authentication-bypass","cve"],"_cs_type":"advisory","_cs_vendors":["Schneider Electric"],"content_html":"\u003cp\u003eSchneider Electric has identified a vulnerability in its PowerChute Serial Shutdown software, which is used for UPS management and system energy control. The vulnerability, tracked as CVE-2026-13348, is an instance of CWE-307: Improper Restriction of Excessive Authentication Attempts. This flaw exists in versions 1.5 and prior of the application.\u003c/p\u003e\n\u003cp\u003eThe vulnerability allows an attacker to perform an arbitrary number of authentication attempts against the software when redirect handling is disabled. Because the application fails to adequately throttle or block repeated login requests, it is susceptible to brute-force attacks. Successful exploitation could lead to unauthorized access to a user account, potentially allowing an adversary to manipulate power management settings or disrupt critical system operations. Given that this software often operates in industrial, energy, and IT environments, unauthorized access poses a risk to operational stability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects users of PowerChute Serial Shutdown across multiple sectors including energy, manufacturing, and commercial facilities worldwide. If exploited, an attacker could gain administrative or user-level access to the application, resulting in the potential disruption of system shutdowns, energy management services, and unauthorized access to system configuration data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the remediation of CVE-2026-13348 by upgrading all instances of PowerChute Serial Shutdown to version 1.6 or later.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade PowerChute Serial Shutdown on all Windows hosts to v1.6 via the official Schneider Electric download portal.\u003c/li\u003e\n\u003cli\u003eUpgrade PowerChute Serial Shutdown on all Linux hosts to v1.6 via the official Schneider Electric download portal.\u003c/li\u003e\n\u003cli\u003eEnsure that PowerChute management interfaces are isolated from public-facing networks and restricted to trusted administrative segments, as recommended in the Schneider Electric Security Handbook.\u003c/li\u003e\n\u003cli\u003eMonitor authentication logs for the PowerChute application for patterns indicative of high-frequency login failures or brute-force activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T18:11:06Z","date_published":"2026-09-17T18:11:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-schneider-powerchute-auth/","summary":"Schneider Electric PowerChute Serial Shutdown version 1.5 and prior contains an improper restriction of excessive authentication attempts vulnerability (CVE-2026-13348) that may allow unauthorized account access via brute-force.","title":"Authentication Bypass Vulnerability in Schneider Electric PowerChute Serial Shutdown","url":"https://feed.craftedsignal.io/briefs/2026-09-schneider-powerchute-auth/"}],"language":"en","title":"CraftedSignal Threat Feed - PowerChute Serial Shutdown (\u003c= 1.5)","version":"https://jsonfeed.org/version/1.1"}