CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Schneider Electric Easergy MiCOM Px40 Series

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2263

As cited

Copy frozen at (site build).

vulnerabilities

Schneider Electric Easergy MiCOM Px40 Series

Schneider Electric has disclosed a vulnerability (CVE-2026-4832) in its Easergy MiCOM Px40 Series protection relays affecting multiple product versions across the series. The vulnerability allows unauthenticated attackers to access sensitive device identification information through the SNMP protocol via hard-coded credentials with a CVSS score of 5.3. Schneider Electric recommends upgrading firmware to patched versions or implementing network segmentation, firewalls, and VPN controls for organizations that cannot immediately patch.

Why it matters: Organizations operating Medium Voltage, High Voltage, or Extra High Voltage distribution systems using affected Easergy MiCOM Px40 relays must identify their specific product versions and either apply firmware patches or immediately implement network isolation controls to prevent unauthorized access to critical power grid equipment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Schneider Electric Easergy MiCOM Px40 Series

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Schneider Electric Easergy MiCOM Px40 Series

Schneider Electric disclosed CVE-2026-4832, a hard-coded credentials vulnerability (CVSS 5.3) in the Easergy MiCOM Px40 Series protection relays used in medium and high voltage distribution. Unauthenticated attackers can interrogate the SNMP port to access basic device identification information. Affected versions span multiple product lines (P14x through P849 series), with firmware patches available at specific version thresholds for each model.

Why it matters: Organizations operating Schneider Electric protection relays in critical infrastructure (energy, manufacturing, transportation) must patch affected firmware versions or apply network isolation controls immediately to prevent unauthorized device reconnaissance on SNMP-enabled systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Schneider Electric Easergy MiCOM Px40 Series

Schneider Electric disclosed CVE-2026-4832, a hard-coded credentials vulnerability (CVSS 5.3) in the Easergy MiCOM Px40 Series protection relays used in medium and high voltage distribution. Unauthenticated attackers can interrogate the SNMP port to access basic device identification information. Affected versions span multiple product lines (P14x through P849 series), with firmware patches available at specific version thresholds for each model.

Why it matters: Organizations operating Schneider Electric protection relays in critical infrastructure (energy, manufacturing, transportation) must patch affected firmware versions or apply network isolation controls immediately to prevent unauthorized device reconnaissance on SNMP-enabled systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary