CISA flags six Schneider PowerChute Serial Shutdown flaws
The fix is straightforward: inventory PowerChute Serial Shutdown 1.4 and earlier, then move Windows and Linux installs to 1.5.
TL;DR
CISA issued an ICS advisory for six vulnerabilities in Schneider Electric PowerChute Serial Shutdown 1.4 and earlier, with a CVSS 3.1 score of 6.1. The flaws include path traversal, credential-reset exposure, denial-of-service conditions and log tampering risks. Contractors, MSPs, ISVs and defense-industrial-base operators using the product in critical infrastructure should upgrade to version 1.5, since the advisory does not identify an interim mitigation that closes every vector.
CISA’s advisory puts the operational work in one place: find Schneider Electric PowerChute Serial Shutdown 1.4 and earlier, then upgrade to version 1.5 on Windows or Linux. The affected versions can allow file overwrite, unauthorized account access, denial-of-service conditions, log manipulation or exposure of sensitive information, depending on the vulnerability and deployment. The advisory lists worldwide deployment across communications, critical manufacturing, energy, healthcare and public health, information technology, and transportation systems. For contractors and managed service providers supporting those environments, this is a patch-and-verify item, not a policy exercise.
Published ·Deep Fathom