CVE-2026-2403
Received Received - Intake
Improper Input Validation in Web Admin Causes Log Truncation

Publication date: 2026-04-14

Last updated on: 2026-04-22

Assigner: Schneider Electric SE

Description
CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-14
Last Modified
2026-04-22
Generated
2026-05-07
AI Q&A
2026-04-14
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
schneider-electric powerchute_serial_shutdown to 1.5 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an improper validation issue (CWE-1284) where the specified quantity in the input is not correctly checked. Specifically, when a Web Admin user modifies the POST /logsettings request payload, it can cause truncation of event and data logs.

This truncation impacts the integrity of the logs, meaning that the logs may be incomplete or altered unintentionally due to this vulnerability.


How can this vulnerability impact me? :

The vulnerability can lead to truncation of event and data logs, which compromises the integrity of these logs.

As a result, important security or operational events might be lost or incomplete, making it difficult to perform accurate auditing, troubleshooting, or forensic analysis.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart