CVE-2026-2400: CRLF Injection
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2400?
CVE-2026-2400 is classified as a medium severity vulnerability due to its potential impact on user credentials.
How do I fix CVE-2026-2400?
To fix CVE-2026-2400, update to a version of Schneider Electric PowerChute Serial Shutdown that is higher than 1.5.
What type of vulnerability is CVE-2026-2400?
CVE-2026-2400 is a CRLF Injection vulnerability that affects the handling of user input in the application.
Who is affected by CVE-2026-2400?
CVE-2026-2400 affects users of Schneider Electric PowerChute Serial Shutdown versions lower than 1.5.
What are the consequences of CVE-2026-2400?
The consequences of CVE-2026-2400 may include unauthorized credential resets for users of the affected application.