CVE-2026-2405
CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2405?
CVE-2026-2405 is considered to be a medium severity vulnerability due to its ability to lead to denial of service.
How do I fix CVE-2026-2405?
To fix CVE-2026-2405, update your Schneider Electric PowerChute Serial Shutdown software to the latest version beyond 1.5.
What are the potential impacts of CVE-2026-2405?
The potential impacts of CVE-2026-2405 include excessive resource consumption and service denial due to flooding the system with requests.
Who is affected by CVE-2026-2405?
CVE-2026-2405 affects users of Schneider Electric PowerChute Serial Shutdown versions below 1.5.
What type of vulnerability is CVE-2026-2405?
CVE-2026-2405 is classified as a CWE-400 Uncontrolled Resource Consumption vulnerability.