Kwetsbaarheden worden geladen…
Kwetsbaarheden worden geladen…
CVE-2026-2399
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload.
Dit record: live koppeling — laatst opgehaald: 25 juli 2026 om 01:36.
Leverancier
Schneider Electric
Product
PowerChute™ Serial Shutdown
Gepubliceerd
25 juli 2026
Laatst gewijzigd
25 juli 2026
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack vector
NETWORK
Privileges required
HIGH
User interaction
NONE
Vertrouwelijkheid
Geen
Integriteit
Hoog
Beschikbaarheid
Hoog
Mogelijk verlies van zicht op of besturing over het proces bij succesvol misbruik.
Beoordeeld als relevant voor de energiesector op basis van: Vermeld in een officiële CISA ICS Advisory, wat directe relevantie voor industriële besturingssystemen bevestigt. Leverancier "Schneider Electric" is een bekende leverancier van apparatuur voor de energiesector.
Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).
IACS Radar-duiding
Classificatie is voorlopig; handmatige verificatie door een OT-securityanalist wordt aanbevolen.
Geclassificeerd door IACS Radar-analysepijplijn (geautomatiseerd) op 25 juli 2026.
IACS Radar-duiding
IEC 62443-mapping
Automatische IACS Radar-duiding op basis van de gerapporteerde CWE-zwakteclassificatie; geen officiële certificeringsuitspraak.