Improper Authentication Attempts Vulnerability in Schneider Electric's Products
CVE-2026-13348

6.9MEDIUM

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-13348?

A vulnerability exists in various Schneider Electric products where improper handling of authentication attempts may allow attackers to exploit the system. By exploiting this flaw, an attacker could execute an arbitrary number of authentication attempts without restrictions, particularly when redirect handling is turned off. This security loophole elevates the risk of unauthorized account access and could lead to further security breaches if not addressed promptly.

Affected Version(s)

PowerChute™ Serial Shutdown Versions 1.5 and prior

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.