CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints.
References
Configurations
History
22 Apr 2026, 14:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf - Vendor Advisory | |
| CPE | cpe:2.3:a:schneider-electric:powerchute_serial_shutdown:*:*:*:*:*:*:*:* | |
| First Time |
Schneider-electric
Schneider-electric powerchute Serial Shutdown |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
14 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 16:16
Updated : 2026-04-22 14:11
NVD link : CVE-2026-2402
Mitre link : CVE-2026-2402
CVE.ORG link : CVE-2026-2402
JSON object : View
Products Affected
schneider-electric
- powerchute_serial_shutdown
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
