PT-2026-32672 · Apc · Powerchute Serial Shutdown
Published
2026-04-14
·
Updated
2026-04-19
·
CVE-2026-2400
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PowerChute Serial Shutdown (affected versions not specified)
Description
Improper neutralization of CRLF sequences, also known as CRLF Injection, occurs when the application fails to properly filter carriage return and line feed characters. This issue can be triggered when a Web Admin user modifies the payload of the 'POST /setPCBEDesc' request, potentially leading to the reset of application user credentials or a denial of service condition via specially crafted POST requests.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerchute Serial Shutdown