Kwetsbaarheden worden geladen…
Kwetsbaarheden worden geladen…
CVE-2026-2401
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker.
Dit record: live koppeling — laatst opgehaald: 25 juli 2026 om 01:36.
Leverancier
Schneider Electric
Product
PowerChute™ Serial Shutdown
Gepubliceerd
25 juli 2026
Laatst gewijzigd
25 juli 2026
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Attack vector
LOCAL
Privileges required
LOW
User interaction
REQUIRED
Vertrouwelijkheid
Beperkt
Integriteit
Geen
Beschikbaarheid
Geen
Beperkte impact op beschikbaarheid; risico ligt vooral bij vertrouwelijkheid of integriteit van procesdata.
Beoordeeld als relevant voor de energiesector op basis van: Vermeld in een officiële CISA ICS Advisory, wat directe relevantie voor industriële besturingssystemen bevestigt. Leverancier "Schneider Electric" is een bekende leverancier van apparatuur voor de energiesector.
Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).
IACS Radar-duiding
Classificatie is voorlopig; handmatige verificatie door een OT-securityanalist wordt aanbevolen.
Geclassificeerd door IACS Radar-analysepijplijn (geautomatiseerd) op 25 juli 2026.
IACS Radar-duiding
IEC 62443-mapping
Automatische IACS Radar-duiding op basis van de gerapporteerde CWE-zwakteclassificatie; geen officiële certificeringsuitspraak.