Schneider-electric
Schneider-electric Powerchute Serial Shutdown: vulnerabilidades y CVE
Schneider-electric Powerchute Serial Shutdown tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2405 | Media (5.3) | 0.24% | — | 14 abr 2026 | CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout requests. |
| CVE-2026-2404 | Media (6.9) | 0.19% | — | 14 abr 2026 | CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload. |
| CVE-2026-2403 | Media (5.3) | 0.17% | — | 14 abr 2026 | CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload. |
| CVE-2026-2402 | Media (6.9) | 0.27% | — | 14 abr 2026 | CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with… |
| CVE-2026-2401 | Baja (2.4) | 0.10% | — | 14 abr 2026 | CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker. |
| CVE-2026-2400 | Media (5.3) | 0.23% | — | 14 abr 2026 | CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload. |
| CVE-2026-2399 | Media (6.9) | 0.20% | — | 14 abr 2026 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep… |
Otros productos de Schneider-electric
Struxureware Data Center Expert · 49Interactive Graphical Scada System · 43Modicon M580 Firmware · 41Modicon M340 Firmware · 39Modicon M340 Bmxp342020 Firmware · 32Modicon M340 Bmxp3420302 Firmware · 28Modicon M340 Bmxp341000 Firmware · 27Ecostruxure Control Expert · 26Modicon M340 Bmxp342000 Firmware · 25Modicon Quantum Firmware · 25Modicon M340 Bmxp3420102 Firmware · 25Easergy T300 Firmware · 24