CVE-2026-2405

MEDIUM

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger d...

Affects 1 product across 2 vendors.

BCS4.74
CVSS 3.16.5
CVSS v45.3
EPSS0.2%
Percentile16th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-400: Uncontrolled Resource Consumption (DoS)

Software does not properly limit resource usage, allowing an attacker to exhaust CPU, memory, disk, or bandwidth.

Related Attack Patterns (CAPEC)
CAPEC-147 XML Ping of the Death
via CWE-400
CAPEC-492 Regular Expression Exponential Blowup
via CWE-400
CAPEC-227 Sustained Client Engagement
via CWE-400

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability exists in the system that could lead to excessive troubleshooting zip file creation and denial of service due to uncontrolled resource consumption when a Web Admin user floods the system with POST /helpabout requests.

BSID: BS-2026-GLOBAL-078769-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-2405?
A vulnerability exists in the system that could lead to excessive troubleshooting zip file creation and denial of service due to uncontrolled resource consumption when a Web Admin user floods the system with POST /helpabout requests.
What is the CVSS score for CVE-2026-2405?
CVE-2026-2405 has CVSS 6.5 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. EPSS: 0.2%.
Is CVE-2026-2405 actively exploited?
No confirmed active exploitation of CVE-2026-2405 as of 2026-07-10.
How do I remediate CVE-2026-2405?
Priority: HIGH. Advisory: https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf PSIRT: [email protected]
What systems are affected by CVE-2026-2405?
CVE-2026-2405 affects: Schneider-Electric, Wolfram Schneider.
Vulnerability Details
CVE IDCVE-2026-2405
BSIDBS-2026-GLOBAL-078769-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Published2026-07-09
Last Modified2026-07-09
ICS Relevance70%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown <=1.4 CVSS Vendor Equipment Vulnerabilities v3 6.1 SuSE, Schneide

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves a Web Admin user sending a large number of POST requests to the /helpabout endpoint, which triggers the creation of troubleshooting zip files. This can exhaust system resources, leading to a denial of service.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Schneider-Electric Powerchute Serial Shutdown
Wolfram Schneider &mdash;
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 16 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash5dd8ec225ebca62e5e8ecd936e8c087fb3362f2f27fc7326f50efb842a1b67119b5b3cbea022ddc8f16de4b099acc9a3a6c8f9f3846fdec77e957539ac314a67
Related CVEs affecting Schneider-Electric
CVE-2011-4861 10.0 The modbus_125_handler function in the Schneider Electric Quantum Ethernet Mo... CVE-2013-0657 10.0 Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA... CVE-2020-11897 10.0 The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multipl... CVE-2020-11896 10.0 The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related ... CVE-2013-3075 10.0 Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3...
View all Schneider-Electric CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →