🛡 VULNERABILIDADES 🛡

Apagado en serie de PowerChute de Schneider Electric

🛡CyberObservatorio
Idioma

Apagado en serie de PowerChute de Schneider Electric

Fuente: CISA Alerts

La explotación exitosa de las vulnerabilidades identificadas en el software PowerChute Serial Shutdown de Schneider Electric podría permitir a los atacantes llevar a cabo una serie de acciones maliciosas de considerable gravedad. Estas incluyen la posibilidad de sobrescribir archivos críticos del sistema, falsificar o inyectar datos de registro maliciosos, obtener acceso no autorizado a cuentas de usuario, provocar condiciones de denegación de servicio, truncar o alterar información de registro, restablecer credenciales de usuario o incluso exponer información sensible. Esta situación subraya la importancia de mantener actualizados los sistemas y de aplicar las mitigaciones adecuadas.

Las versiones afectadas de PowerChute Serial Shutdown son todas las anteriores a la 1.5. Esta aplicación presenta vulnerabilidades relacionadas con restricciones inadecuadas en los caminos de archivos, lo que podría permitir que archivos críticos sean sobrescritos con datos no intencionados. Las vulnerabilidades han sido catalogadas con las siguientes identificaciones de vulnerabilidad (CVE): CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400 y CVE-2026-2401.

Para mitigar los riesgos asociados, los proveedores SuSE, Schneider Electric, Red Hat y Microsoft han identificado una serie de soluciones específicas y técnicas que los usuarios pueden aplicar. La versión 1.5 de PowerChute Serial Shutdown incluye correcciones para las vulnerabilidades mencionadas y está disponible para su descarga tanto en Windows como en Linux. Se puede acceder a la descarga para Windows a través del siguiente enlace: [PowerChute Windows](https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/), y para Linux en: [PowerChute Linux](https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).

Es fundamental que los usuarios sigan las instrucciones específicas y las directrices de endurecimiento que se pueden encontrar en el Manual de Seguridad de Schneider Electric. Este documento proporciona información detallada sobre cómo implementar las mitigaciones necesarias para proteger los sistemas afectados. Además, las versiones de PowerChute Serial Shutdown que han sido corregidas incluyen la 1.5 instalada en Microsoft Windows, Red Hat Enterprise Linux y SuSE Linux, las cuales son seguras para las vulnerabilidades CVE-2026-2399 y CVE-2026-2404.

Para obtener más información, se puede consultar el aviso de seguridad de Schneider Electric CPCERT, SEVD-2026-104-01, que detalla múltiples vulnerabilidades en PowerChute Serial Shutdown. Este aviso está disponible en formato PDF [aquí](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf) y también en formato CSAF [aquí](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).

Las vulnerabilidades se relacionan con el CWE-22, que se refiere a la limitación inapropiada de un nombre de ruta a un directorio restringido ('Path Traversal'). Además, PowerChute presenta una vulnerabilidad de codificación de salida inadecuada, lo que puede permitir que entradas manipuladas se reflejen en los archivos de registro de manera inesperada. Por lo tanto, es imprescindible que los usuarios de PowerChute tomen medidas proactivas para asegurar sus entornos frente a estas amenazas.

**Solución del proveedor**

Para obtener información adicional, se puede consultar el aviso de seguridad emitido por Schneider Electric, correspondiente a la referencia CPCERT SEVD-2026-104-01, que detalla múltiples vulnerabilidades en el sistema PowerChute Serial Shutdown. Este aviso se encuentra disponible en formato PDF y en una versión estructurada según el formato CSAF, accesibles a través de los siguientes enlaces: [PDF](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf) y [CSAF](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).

Dentro de las vulnerabilidades identificadas, se destaca la relacionada con el código CWE-116, que se refiere a una codificación o escape inadecuado de la salida, lo que permite que PowerChute sufra de limitaciones insuficientes en los intentos de autenticación repetidos a través de múltiples puntos finales. Esta falla podría dar lugar a la posibilidad de ataques de fuerza bruta que comprometan la integridad del sistema.

En cuanto a la corrección de esta vulnerabilidad, se ha identificado el CVE-2026-2402, que afecta a las versiones de PowerChute Serial Shutdown 1.4 y anteriores. La versión 1.5, que ya incluye las correcciones necesarias, está disponible para descarga tanto para Windows como para Linux mediante los siguientes enlaces: [Windows](https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/) y [Linux](https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).

Además, se ha publicado un manual de seguridad que contiene instrucciones específicas y directrices de fortalecimiento para mitigar esta y otras vulnerabilidades. Este manual puede ser consultado en el siguiente enlace: [Manual de Seguridad](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).

Por otro lado, las versiones 1.5 de PowerChute Serial Shutdown instaladas en sistemas operativos como Microsoft Windows, Red Hat Enterprise Linux y SuSE Linux cuentan con las correcciones necesarias para la vulnerabilidad CVE-2026-2402. Esto subraya la importancia de mantener los sistemas actualizados para protegerse contra amenazas potenciales.

En relación a otras vulnerabilidades, el CWE-307 se refiere a una restricción inadecuada de los intentos de autenticación excesivos, lo que hace que PowerChute sea susceptible a un consumo incontrolado de recursos cuando se activan ciertas operaciones del sistema de manera excesiva. Para abordar esto, se han sugerido soluciones específicas y medidas de mitigación por parte de SuSE, Schneider Electric, Red Hat y Microsoft, que los usuarios pueden aplicar para reducir el riesgo asociado a los CVEs-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400 y CVE-2026-2401. Al igual que con la CVE-2026-2402, la versión 1.5 de PowerChute Serial Shutdown es fundamental para corregir estas vulnerabilidades, y se puede descargar desde los mismos enlaces mencionados anteriormente.

En cuanto a la mitigación de vulnerabilidades en PowerChute, se recomienda a los usuarios consultar las instrucciones específicas y las pautas de endurecimiento en el *Security Handbook*, disponible a través del siguiente enlace: [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN). Este manual proporciona directrices detalladas para abordar las vulnerabilidades identificadas.

La versión 1.5 de PowerChute Serial Shutdown, instalada en sistemas operativos Microsoft Windows, Red Hat Enterprise Linux y SuSE Linux, corrige las vulnerabilidades asociadas a CVE-2026-2405. Esta actualización es esencial para asegurar que el software no esté expuesto a los riesgos que estas vulnerabilidades podrían conllevar, como la pérdida de datos críticos y la falta de visibilidad en el comportamiento del sistema.

Para aquellos interesados en profundizar más sobre las vulnerabilidades, Schneider Electric ha publicado el aviso de seguridad CPCERT SEVD-2026-104-01, que detalla múltiples vulnerabilidades en PowerChute Serial Shutdown. Este aviso está disponible tanto en versión PDF como en formato CSAF, que se puede acceder en los siguientes enlaces: [PDF Version](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf) y [CSAF Version](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).

Cabe destacar que la vulnerabilidad clasificada como CWE-400, que se refiere al consumo descontrolado de recursos, afecta a PowerChute debido a la validación inadecuada de entradas relacionadas con cantidades. Esto puede provocar que los registros de eventos y datos se truncen, ocasionando la pérdida de información de auditoría crucial que es necesaria para evaluar el correcto funcionamiento del sistema.

Las empresas involucradas, incluyendo SuSE, Schneider Electric, Red Hat y Microsoft, han identificado medidas específicas que los usuarios pueden aplicar para mitigar el riesgo asociado con diversas vulnerabilidades (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401). La versión 1.5 de PowerChute Serial Shutdown es la única que incorpora correcciones para estas vulnerabilidades y está disponible para descarga en las siguientes plataformas: [Windows](https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/) y [Linux](https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).

Por último, es importante mencionar que la vulnerabilidad clasificada como CWE-1284 se relaciona con la validación inadecuada de cantidades especificadas en las entradas. Esta falla permite que se manejen de manera incorrecta las secuencias de nueva línea en ciertos datos, lo que podría resultar en modificaciones inesperadas de la configuración relacionada. La atención a estas vulnerabilidades es crítica para mantener la integridad y la seguridad de los sistemas que dependen de PowerChute.

Los proveedores SuSE, Schneider Electric, Red Hat y Microsoft han identificado una serie de soluciones y mitigaciones específicas que los usuarios pueden implementar para reducir el riesgo asociado a varias vulnerabilidades críticas en sus sistemas. Estas vulnerabilidades están catalogadas bajo los identificadores CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400 y CVE-2026-2401. En particular, la versión 1.5 de PowerChute Serial Shutdown, que corrige estas vulnerabilidades, está disponible para su descarga en sistemas operativos Windows y Linux. Los enlaces de descarga son los siguientes: para Windows se puede acceder a [este enlace](https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/) y para Linux a [este otro](https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).

Además, los usuarios pueden encontrar instrucciones específicas y directrices de endurecimiento en el manual de seguridad de Schneider Electric, que se puede consultar en [este enlace](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN). Es importante destacar que la versión 1.5 de PowerChute Serial Shutdown instalada en sistemas Microsoft Windows, Red Hat Enterprise Linux y SuSE Linux incluye las correcciones pertinentes para la vulnerabilidad CVE-2026-2400 y CVE-2026-2401, asegurando así que los usuarios estén protegidos contra posibles ataques que exploten estas debilidades.

Para más información, se puede consultar el aviso de seguridad SEVD-2026-104-01 emitido por Schneider Electric, que detalla múltiples vulnerabilidades en PowerChute Serial Shutdown. Este aviso está disponible en formato PDF [aquí](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf) y también en formato CSAF [en este enlace](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).

Cabe señalar que la vulnerabilidad en cuestión está relacionada con el CWE-93, que se refiere a la "Neutralización Inadecuada de Secuencias CRLF" (inyección CRLF), lo que implica que PowerChute es susceptible a un registro inapropiado de información sensible durante ciertas operaciones iniciadas por el usuario. Este tipo de vulnerabilidad puede tener graves implicaciones en la seguridad, ya que puede permitir a un atacante ejecutar comandos no autorizados o acceder a datos confidenciales. Por ello, es crucial que los usuarios de PowerChute tomen las medidas necesarias para actualizar sus sistemas y seguir las directrices de seguridad proporcionadas por los proveedores.

Recientemente, Schneider Electric ha emitido un aviso de seguridad, identificado como SEVD-2026-104-01, en el que se detallan múltiples vulnerabilidades en su software PowerChute Serial Shutdown. Este documento, que se puede consultar en su versión PDF [aquí](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf) y en su versión CSAF [aquí](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json), proporciona información crítica sobre las vulnerabilidades identificadas y las medidas recomendadas para mitigar su impacto.

Un aspecto relevante a destacar es la inclusión de la CWE-532, que se refiere a la inserción de información sensible en archivos de registro. Esto subraya la importancia de manejar adecuadamente la información que se registra para evitar exposiciones no deseadas.

La Agencia de Seguridad de Infraestructura y Ciberseguridad de EE. UU., conocida como CISA, ha instado a los usuarios a adoptar medidas defensivas que reduzcan el riesgo de explotación de estas vulnerabilidades. En este sentido, se recomienda minimizar la exposición en red de todos los dispositivos y sistemas de control, asegurando que no sean accesibles desde Internet. Además, se sugiere situar las redes de control y los dispositivos remotos detrás de cortafuegos, aislándolos de las redes empresariales para añadir una capa adicional de seguridad.

Cuando sea necesario el acceso remoto, se aconseja utilizar métodos más seguros, como las Redes Privadas Virtuales (VPN). Sin embargo, es crucial tener en cuenta que las VPN pueden presentar vulnerabilidades, por lo que deben actualizarse a la versión más reciente disponible y su seguridad dependerá de los dispositivos conectados. CISA también recuerda a las organizaciones que realicen un análisis de impacto y evaluación de riesgos adecuados antes de implementar cualquier medida defensiva.

Adicionalmente, CISA proporciona una sección dedicada a las prácticas recomendadas para la seguridad de sistemas de control en su página web de ICS. Entre los recursos disponibles, se encuentran guías que detallan las mejores prácticas para la defensa cibernética, incluido un documento titulado "Mejorando la Ciberseguridad de los Sistemas de Control Industrial con Estrategias de Defensa en Profundidad".

La agencia también alienta a las organizaciones a implementar estrategias de ciberseguridad recomendadas para una defensa proactiva de los activos de ICS. Para aquellos que busquen más orientación sobre la mitigación de riesgos, se encuentra disponible el documento técnico ICS-TIP-12-146-01B, que ofrece estrategias de detección y mitigación de intrusiones cibernéticas dirigidas.

En caso de observar actividades sospechosas que puedan ser maliciosas, CISA sugiere que las organizaciones sigan los procedimientos internos establecidos y reporten sus hallazgos para su seguimiento y correlación con otros incidentes.

Por último, CISA hace hincapié en que los usuarios deben protegerse contra los ataques de ingeniería social, evitando hacer clic en enlaces web o abrir archivos adjuntos en correos electrónicos no solicitados. Para más información sobre cómo reconocer y evitar estafas por correo electrónico, se puede consultar su guía sobre el tema, así como su documento sobre cómo evitar ataques de ingeniería social y phishing. Hasta el momento, CISA no ha recibido reportes de explotación pública específica que apunte a estas vulnerabilidades.

Schneider Electric PowerChute Serial Shutdown

Source: CISA Alerts

View CSAF Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: Expand All + PowerChute is vulnerable to improper restriction of file paths, which could allow critical system files to be overwritten with unintended data. View CVE Details Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ MitigationSpecific instructions and hardening guidelines for these mitigations can be found in the Security Handbook.https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN Vendor fixThe following product versions have been fixed: PowerChute Serial Shutdown Version 1.5 installed on Microsoft Windows are fixed versions for CVE-2026-2399. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Red Hat Enterprise Linux are fixed versions for CVE-2026-2399. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on SuSE Linux are fixed versions for CVE-2026-2399. Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json Relevant CWE:CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') PowerChute is vulnerable to improper output encoding, which may allow crafted input to be reflected in log files in unexpected ways. View CVE Details Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ MitigationSpecific instructions and hardening guidelines for these mitigations can be found in the Security Handbook.https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Microsoft Windows are fixed versions for CVE-2026-2404. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Red Hat Enterprise Linux are fixed versions for CVE-2026-2404. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on SuSE Linux are fixed versions for CVE-2026-2404. Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json Relevant CWE:CWE-116 Improper Encoding or Escaping of Output PowerChute is vulnerable to insufficient limitations on repeated authentication attempts across multiple endpoints. View CVE Details Vendor fix(CVE-2026-2402) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Vendor fix(CVE-2026-2402) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ MitigationSpecific instructions and hardening guidelines for these mitigations can be found in the Security Handbook.https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Microsoft Windows are fixed versions for CVE-2026-2402. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Red Hat Enterprise Linux are fixed versions for CVE-2026-2402. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on SuSE Linux are fixed versions for CVE-2026-2402. Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json Relevant CWE:CWE-307 Improper Restriction of Excessive Authentication Attempts PowerChute is vulnerable to uncontrolled resource consumption when certain system operations are triggered excessively. View CVE Details Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ MitigationSpecific instructions and hardening guidelines for these mitigations can be found in the Security Handbook.https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Microsoft Windows are fixed versions for CVE-2026-2405. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Red Hat Enterprise Linux are fixed versions for CVE-2026-2405. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on SuSE Linux are fixed versions for CVE-2026-2405. Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json Relevant CWE:CWE-400 Uncontrolled Resource Consumption PowerChute is vulnerable to improper validation of quantity‑related inputs, which can cause event and data logs to be truncated. As a result, important audit information may be lost, reducing visibility into system behavior. View CVE Details Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ MitigationSpecific instructions and hardening guidelines for these mitigations can be found in the Security Handbook.https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Microsoft Windows are fixed versions for CVE-2026-2403. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Red Hat Enterprise Linux are fixed versions for CVE-2026-2403. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on SuSE Linux are fixed versions for CVE-2026-2403. Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json Relevant CWE:CWE-1284 Improper Validation of Specified Quantity in Input PowerChute is vulnerable to improper handling of newline sequences in certain inputs, enabling unexpected modification of configuration‑related data. View CVE Details Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ MitigationSpecific instructions and hardening guidelines for these mitigations can be found in the Security Handbook.https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Microsoft Windows are fixed versions for CVE-2026-2400. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Red Hat Enterprise Linux are fixed versions for CVE-2026-2400. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on SuSE Linux are fixed versions for CVE-2026-2400. Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json Relevant CWE:CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') PowerChute is vulnerable to improper logging of sensitive information when certain user‑triggered operations occur. View CVE Details Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Vendor fixSuSE, Schneider Electric, Red Hat, and Microsoft have identified the following specific workarounds and mitigations users can apply to reduce risk: (CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401) PowerChute Serial Shutdown Versions 1.4 and prior: Version 1.5 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: Windows (https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/). Linux (https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/).https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ MitigationSpecific instructions and hardening guidelines for these mitigations can be found in the Security Handbook.https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Microsoft Windows are fixed versions for CVE-2026-2401. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on Red Hat Enterprise Linux are fixed versions for CVE-2026-2401. Vendor fixPowerChute Serial Shutdown Version 1.5 installed on SuSE Linux are fixed versions for CVE-2026-2401. Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf Vendor fixFor more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-104-01 Multiple Vulnerabilities on PowerChute Serial Shutdown - SEVD-2026-104-01 PDF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf). Multiple Vulnerabilities on PowerChute Serial Shutdown- SEVD-2026-104-01 CSAF Version (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json).https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-104-01.json Relevant CWE:CWE-532 Insertion of Sensitive Information into Log File This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

Apagado en serie de PowerChute de Schneider Electric | Ciberseguridad - NarcoObservatorio