CVE-2026-2405
Uncontrolled Resource Consumption in Web Admin Causes DoS
Publication date: 2026-04-14
Last updated on: 2026-04-22
Assigner: Schneider Electric SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| schneider-electric | powerchute_serial_shutdown | to 1.5 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a CWE-400 Uncontrolled Resource Consumption issue. It occurs when a Web Admin user sends a large number of POST /helpabout requests, causing the system to create excessive troubleshooting zip files. This excessive resource usage can lead to a denial of service.
How can this vulnerability impact me? :
The vulnerability can impact you by causing a denial of service condition. When exploited, it can overwhelm the system with resource consumption due to excessive creation of troubleshooting zip files, potentially making the system unavailable or degraded in performance.