As cited
Copy frozen at (site build).
vulnerabilities
Schneider Electric Easergy MiCOM Px40 Series
Schneider Electric has disclosed a vulnerability (CVE-2026-4832) in its Easergy MiCOM Px40 Series protection relays affecting multiple product versions across the series. The vulnerability allows unauthenticated attackers to access sensitive device identification information through the SNMP protocol via hard-coded credentials with a CVSS score of 5.3. Schneider Electric recommends upgrading firmware to patched versions or implementing network segmentation, firewalls, and VPN controls for organizations that cannot immediately patch.
Why it matters: Organizations operating Medium Voltage, High Voltage, or Extra High Voltage distribution systems using affected Easergy MiCOM Px40 relays must identify their specific product versions and either apply firmware patches or immediately implement network isolation controls to prevent unauthorized access to critical power grid equipment.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Schneider Electric Easergy MiCOM Px40 Series
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Schneider Electric Easergy MiCOM Px40 Series
Schneider Electric disclosed CVE-2026-4832, a hard-coded credentials vulnerability (CVSS 5.3) in the Easergy MiCOM Px40 Series protection relays used in medium and high voltage distribution. Unauthenticated attackers can interrogate the SNMP port to access basic device identification information. Affected versions span multiple product lines (P14x through P849 series), with firmware patches available at specific version thresholds for each model.
Why it matters: Organizations operating Schneider Electric protection relays in critical infrastructure (energy, manufacturing, transportation) must patch affected firmware versions or apply network isolation controls immediately to prevent unauthorized device reconnaissance on SNMP-enabled systems.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Schneider Electric Easergy MiCOM Px40 Series
Schneider Electric disclosed CVE-2026-4832, a hard-coded credentials vulnerability (CVSS 5.3) in the Easergy MiCOM Px40 Series protection relays used in medium and high voltage distribution. Unauthenticated attackers can interrogate the SNMP port to access basic device identification information. Affected versions span multiple product lines (P14x through P849 series), with firmware patches available at specific version thresholds for each model.
Why it matters: Organizations operating Schneider Electric protection relays in critical infrastructure (energy, manufacturing, transportation) must patch affected firmware versions or apply network isolation controls immediately to prevent unauthorized device reconnaissance on SNMP-enabled systems.
- Source published
- First seen by Cybersecurity Tracker