Schneider Electric PowerChute Serial Shutdown < 1.6 Improper Restriction of Excessive Authentication Attempts (SEVD-2026-223-01)

medium Nessus Plugin ID 335181

Synopsis

Schneider Electric PowerChute Serial Shutdown installed on the remote host is affected by a vulnerability.

Description

The version of Schneider Electric PowerChute Serial Shutdown installed on the remote host is prior to 1.6. It is, therefore, affected by a vulnerability.

- CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled. (CVE-2026-13348)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Schneider Electric PowerChute Serial Shutdown version 1.6 or later.

See Also

https://www.se.com/.well-known/csaf/2026/sevd-2026-223-01.json

http://www.nessus.org/u?f5f9a9b6

Plugin Details

Severity: Medium

ID: 335181

File Name: schneider_electric_powerchute_serial_shutdown_1_6.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 8/13/2026

Updated: 8/13/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-13348

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/a:schneider-electric:powerchute_serial_shutdown

Required KB Items: installed_sw/Schneider Electric PowerChute Serial Shutdown

Patch Publication Date: 8/11/2026

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-13348

CWE: 307