Issue: PowerChute Network Shutdown is affected by CVE-2023-20860 and CVE-2023-20861
Products: PowerChute Network Shutdown v5.0
Environment: All support OS
Cause: spring 5.3.22 vulnerability
Solution: Update the spring library to mitigate CVE-2023-20860 and CVE-2023-20861
Steps: On a Windows system
- Stop PowerChute Service.
- Open a command prompt as an administrator and enter net stop PCNS1
- Remove old JAR files from the group1\lib folder.
- The default path for PowerChute is C:\Program Files\APC\PowerChute\group1
- Remove spring-aop-5.3.22.jar spring-beans-5.3.22.jar spring-context-5.3.22.jar spring-core-5.3.22.jar spring-expression-5.3.22.jar spring-web-5.3.22.jar
- Copy in new 5.3.29 Spring JAR files. The files are attached as a zip to this FAQ.
- Uncompress the zip and copy the contents of the Spring5.3.29 folder to group1\lib
- Start PowerChute service.
- From the command prompt as an administrator enter net start PCNS1
Steps: on Linux system
NOTE: Linux is case sensitive when entering command and file names.
- Stop PowerChute Service.
- Open a terminal window with root privileges and enter sudo systemctl stop PowerChute
- Remove old JAR files from the group1/lib folder.
- The default path for PowerChute is /opt/APC/PowerChute/group1
- To remove the file cd to /opt/APC/PowerChute/group1/lib
- remove spring-aop-5.3.22.jar spring-beans-5.3.22.jar spring-context-5.3.22.jar spring-core-5.3.22.jar spring-expression-5.3.22.jar spring-web-5.3.22.jar
- The command is sudo rm -rf spring-*
- Copy in new 5.3.29 Spring JAR files. The files are attached as a zip to this FAQ.
- Uncompress the zip and copy the contents of the Spring5.3.29 folder to group1/lib
- Start PowerChute service.
- From the terminal, as an administrator, enter sudo systemctl start PowerChute
Released for: Schneider Electric Hong Kong
Issue: PowerChute Network Shutdown is affected by CVE-2023-20860 and CVE-2023-20861
Products: PowerChute Network Shutdown v5.0
Environment: All support OS
Cause: spring 5.3.22 vulnerability
Solution: Update the spring library to mitigate CVE-2023-20860 and CVE-2023-20861
Steps: On a Windows system
- Stop PowerChute Service.
- Open a command prompt as an administrator and enter net stop PCNS1
- Remove old JAR files from the group1\lib folder.
- The default path for PowerChute is C:\Program Files\APC\PowerChute\group1
- Remove spring-aop-5.3.22.jar spring-beans-5.3.22.jar spring-context-5.3.22.jar spring-core-5.3.22.jar spring-expression-5.3.22.jar spring-web-5.3.22.jar
- Copy in new 5.3.29 Spring JAR files. The files are attached as a zip to this FAQ.
- Uncompress the zip and copy the contents of the Spring5.3.29 folder to group1\lib
- Start PowerChute service.
- From the command prompt as an administrator enter net start PCNS1
Steps: on Linux system
NOTE: Linux is case sensitive when entering command and file names.
- Stop PowerChute Service.
- Open a terminal window with root privileges and enter sudo systemctl stop PowerChute
- Remove old JAR files from the group1/lib folder.
- The default path for PowerChute is /opt/APC/PowerChute/group1
- To remove the file cd to /opt/APC/PowerChute/group1/lib
- remove spring-aop-5.3.22.jar spring-beans-5.3.22.jar spring-context-5.3.22.jar spring-core-5.3.22.jar spring-expression-5.3.22.jar spring-web-5.3.22.jar
- The command is sudo rm -rf spring-*
- Copy in new 5.3.29 Spring JAR files. The files are attached as a zip to this FAQ.
- Uncompress the zip and copy the contents of the Spring5.3.29 folder to group1/lib
- Start PowerChute service.
- From the terminal, as an administrator, enter sudo systemctl start PowerChute
Released for: Schneider Electric Hong Kong




Need help?
Product Selector
Quickly and easily find the right products and accessories for your applications.
Get a Quote
Start your sales enquiry online and an expert will connect with you.
Where to buy?
Easily find the nearest Schneider Electric distributor in your location.
Help Centre
Find support resources for all your needs, in one place.