Improper Restriction of Excessive Authentication Attempts in Schneider Electric Product
CVE-2025-11566
6.9MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 12 November 2025
What is CVE-2025-11566?
A vulnerability affected Schneider Electric products, allowing an attacker on the local network to exploit the /REST/shutdownnow endpoint. By attempting an arbitrary number of authentication attempts with different credentials, the attacker could potentially gain unauthorized access to user accounts. This weakness stems from improper restrictions in authentication logic, which may lead to serious security breaches.
Affected Version(s)
PowerChute Serial Shutdown Versions v1.3 and prior