Schneider Electric PowerChute Serial Shutdown
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-02.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. /strong /p p The following versions of Schneider Electric PowerChute Serial Shutdown are affected: /p ul li PowerChute Serial Shutdown lt;=1.4 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.1 /td td SuSE, Schneider Electric, Red Hat, Microsoft /td td Schneider Electric PowerChute Serial Shutdown /td td Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Encoding or Escaping of Output, Improper Restriction of Excessive Authentication Attempts, Uncontrolled Resource Consumption, Improper Validation of Specified Quantity in Input, Improper Neutralization of CRLF Sequences ('CRLF Injection'), Insertion of Sensitive Information into Log File /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Communications, Critical Manufacturing, Energy, Healthcare and Public Health, Information Technology, Transportation Systems /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong France /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-2399 /a /h3 div class="csaf-accordion-content" p PowerChute is vulnerable to improper restriction of file paths, which could allow critical system files to be overwritten with unintended data. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-2399" View CVE Details /a /p hr h4 Affected Products /h4 h5 Schneider Electric PowerChute Serial Shutdown /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br SuSE, Schneider Electric, Red Hat, Microsoft /div div class="ics-version" strong Product Version: /strong br SuSE, Schneider Electric, Red Hat, Microsoft PowerChute Serial Shutdown: lt;=1.4 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br SuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403,
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by CISA
Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-02
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.