← Back to Feed

Schneider Electric PowerChute Serial Shutdown

CVE-2026-13348

September 17, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown vers:intdot/<=1.5, 1.6 (CVE-2026-13348) CVSS Vendor Equipment Vulnerabilities v3 5.3 Schneider Electric Schneider Electric PowerChute Serial Shutdown Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-13348 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled. View CVE Details Affected Products Schneider Electric PowerChute Serial Shutdown Vendor:Schneider Electric Product Version:PowerChute Serial Shutdown Version 1.5 and prior Product Status:fixed, known_affected Remediations Vendor fixVersion v1.6 of PowerChute Serial Shutdown includes a fix for these vulnerabilities and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Reboot needed: Upon installation, the service is automatically restarted. A customer can validate a successful install by checking the version information in the Control Panel or on the About page within PCSS after logging in. Specific instructions and hardening guidelines...

Key Takeaways

  • Schneider Electric products including NetBotz, Modicon M340, and PowerChute contain security vulnerabilities that could impact industrial control and building management systems.
  • The breadth of affected Schneider Electric products demonstrates the challenge of securing diverse OT product portfolios across industrial and facility management environments.
  • Organizations using Schneider Electric equipment should review the specific CVEs and apply available patches while monitoring for signs of exploitation in their OT environments.
☕ Buy a Coffee