Impact
This vulnerability is a CWE‑307 flaw that allows an attacker to perform an arbitrary number of authentication attempts because the system does not properly restrict excessive login attempts when redirect handling is disabled. The primary impact is that an attacker could gain unauthorized access to a user account on the PowerChute Serial Shutdown device, potentially allowing further compromise of the power management system.
Affected Systems
The affected product is Schneider Electric’s PowerChute Serial Shutdown. No specific version information is provided in the advisory, so the risk applies to all installations of this product that still have the redirect handling disabled.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread documented exploitation yet. The likely attack vector is remote: an adversary can attempt login over the network to the device as long as redirect handling is disabled, exploiting the lack of account lockout or attempt limiting mechanisms.
OpenCVE Enrichment