PatchSiren cyber security CVE debrief
CVE-2025-11566 Schneider Electric CVE debrief
CVE-2025-11566 is a HIGH-severity authentication weakness in Schneider Electric PowerChute Serial Shutdown. CISA’s advisory says a local-network attacker could make an arbitrary number of authentication attempts with different credentials against the /REST/shutdownnow endpoint and potentially gain access to the user account. Schneider Electric lists version v1.4 as the fixed release.
- Vendor
- Schneider Electric
- Product
- PowerChute™ Serial Shutdown
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-11-11
- Original CVE updated
- 2025-11-11
- Advisory published
- 2025-11-11
- Advisory updated
- 2025-11-11
Who should care
Administrators and operators of PowerChute Serial Shutdown deployments, especially systems exposed to local network access paths on Windows or Linux. Industrial and UPS-management environments should prioritize this issue because it affects an authentication boundary on a management endpoint.
Technical summary
The advisory describes a CWE-307 issue: improper restriction of excessive authentication attempts. The affected service exposes the /REST/shutdownnow endpoint, and a local-network attacker can try unlimited credentials without effective throttling or lockout. The source indicates that PowerChute Serial Shutdown v1.4 includes a fix, with vendor download links provided for Windows and Linux.
Defensive priority
High. The issue is network-reachable from the local network, has no user interaction requirement, and is rated CVSS 7.3 (HIGH) in the source advisory. Systems that rely on PowerChute Serial Shutdown for shutdown or power-management operations should remediate promptly.
Recommended defensive actions
- Upgrade PowerChute Serial Shutdown to version v1.4 using the vendor-provided Windows or Linux download.
- Restrict local-network access to the management interface and /REST/shutdownnow endpoint using segmentation or allowlisting.
- Review authentication logs for repeated or high-volume login attempts against PowerChute Serial Shutdown endpoints.
- Follow CISA ICS defense-in-depth and recommended-practices guidance for securing industrial control and management interfaces.
- Validate that any deployed PowerChute Serial Shutdown installations match the vendor advisory and remediation guidance before returning systems to service.
Evidence notes
All factual claims here are drawn from the supplied CISA CSAF advisory for ICSA-25-322-04 / CVE-2025-11566 and its referenced Schneider Electric security notice. The source advisory is dated 2025-11-11 and states the flaw is a CWE-307 improper restriction of excessive authentication attempts against /REST/shutdownnow. The source corpus names Schneider Electric in the advisory title and vendor metadata; the prompt’s vendor field is low-confidence and marked for review, so this debrief uses the advisory naming while avoiding unsupported vendor assumptions.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-11566 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-11566
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-11566 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-11566
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-322-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/us/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-322-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.