Schneider Electric PowerChute Serial Shutdown CRLF Injection Vulnerability Allowing Credential Reset
Vulnerability
A CRLF injection vulnerability has been identified in Schneider Electric's PowerChute Serial Shutdown software, specifically in versions through 1.4. This vulnerability allows a Web Admin user to reset application user credentials by altering the payload of the POST /setPCBEDesc request.
Impact
Exploitation of this vulnerability leads to unauthorized credential resets, allowing users to potentially gain access to accounts with modified credentials.
Remediation
Users can upgrade to version 1.5 of PowerChute Serial Shutdown, which addresses this vulnerability. This version is available for download from the Schneider Electric website. Specific instructions and hardening guidelines can be found in the Security Handbook.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
