As cited
Copy frozen at (site build).
vulnerabilities
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)
Schneider Electric disclosed CVE-2026-4827, an insufficient entropy vulnerability in session management affecting Easergy, EcoStruxure, PowerLogic, and Saitel products used in electrical distribution and substation automation. The flaw enables network-based attackers to hijack sessions and perform unauthorized operations. Fixed versions are available for most affected models, though some Easergy MiCOM P30 and P40 series models are awaiting future patches, with interim network segmentation and session timeout mitigations recommended.
Why it matters: Organizations operating electrical substations, distribution networks, and industrial automation systems using these Schneider Electric products must prioritize patching or implement network isolation immediately to prevent unauthorized control of critical power infrastructure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)
Schneider Electric disclosed CVE-2026-4827, an insufficient entropy vulnerability in session management affecting Easergy, EcoStruxure, PowerLogic, and Saitel products used in electrical distribution and substation automation. The flaw enables network-based attackers to hijack sessions and perform unauthorized operations. Fixed versions are available for most affected models, though some Easergy MiCOM P30 and P40 series models are awaiting future patches, with interim network segmentation and session timeout mitigations recommended.
Why it matters: Organizations operating electrical substations, distribution networks, and industrial automation systems using these Schneider Electric products must prioritize patching or implement network isolation immediately to prevent unauthorized control of critical power infrastructure.
- Source published
- First seen by Cybersecurity Tracker