Description
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.
Published: 2026-09-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a CWE‑307 flaw that allows an attacker to perform an arbitrary number of authentication attempts because the system does not properly restrict excessive login attempts when redirect handling is disabled. The primary impact is that an attacker could gain unauthorized access to a user account on the PowerChute Serial Shutdown device, potentially allowing further compromise of the power management system.

Affected Systems

The affected product is Schneider Electric’s PowerChute Serial Shutdown. No specific version information is provided in the advisory, so the risk applies to all installations of this product that still have the redirect handling disabled.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread documented exploitation yet. The likely attack vector is remote: an adversary can attempt login over the network to the device as long as redirect handling is disabled, exploiting the lack of account lockout or attempt limiting mechanisms.

Generated by OpenCVE AI on September 1, 2026 at 15:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or software update from Schneider Electric for PowerChute Serial Shutdown that addresses the authentication attempt restriction flaw.
  • Enable redirect handling on the device to enforce proper authentication restrictions.
  • Configure and enforce an account lockout policy to limit failed login attempts and monitor for suspicious activity.

Generated by OpenCVE AI on September 1, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric powerchute Serial Shutdown
Vendors & Products Schneider-electric
Schneider-electric powerchute Serial Shutdown

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.
Weaknesses CWE-307
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Schneider-electric Powerchute Serial Shutdown
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2026-09-01T13:31:50.307Z

Reserved: 2026-06-25T15:07:55.948Z

Link: CVE-2026-13348

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T14:17:24.703

Modified: 2026-09-01T14:17:24.703

Link: CVE-2026-13348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:45:03Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts