#VU119888 Improper Restriction of Excessive Authentication Attempts in PowerChute Serial Shutdown - CVE-2025-11566
Published: December 12, 2025
PowerChute Serial Shutdown
Schneider Electric
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected module does not limit the number of password attempts within the /REST/shutdownnow endpoint. A local attacker can perform a brute-force attack and gain access to the user account.