Improper Restriction of Excessive Authentication Attempts in Schneider Electric Product
CVE-2025-11566

6.9MEDIUM

What is CVE-2025-11566?

A vulnerability affected Schneider Electric products, allowing an attacker on the local network to exploit the /REST/shutdownnow endpoint. By attempting an arbitrary number of authentication attempts with different credentials, the attacker could potentially gain unauthorized access to user accounts. This weakness stems from improper restrictions in authentication logic, which may lead to serious security breaches.

Affected Version(s)

PowerChute Serial Shutdown Versions v1.3 and prior

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11566 : Improper Restriction of Excessive Authentication Attempts in Schneider Electric Product