BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

News Vulnerability
VulnerabilityCISA·19d ago

Schneider Electric Easergy MiCOM Px40 Series

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-03.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation) is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk unauthorized exposure of basic device identification through the SNMP protocol. /strong /p p The following versions of Schneider Electric Easergy MiCOM Px40 Series are affected: /p ul li Easergy MiCOM P14x All versions prior to B4A /li li Easergy MiCOM P24x All versions prior to D3A /li li Easergy MiCOM P341 All versions prior to E3F /li li Easergy MiCOM P342, P343, P344, P345 All versions prior to B3F /li li Easergy MiCOM P442, P444 All versions prior to E3A /li li Easergy MiCOM P443, P445, P446, P543, P544, P545, P546 All versions prior to H6A /li li Easergy MiCOM P841 All versions prior to G6A /li li Easergy MiCOM P643 All versions prior to B3F /li li Easergy MiCOM P642, P645 All versions prior to B4A /li li Easergy MiCOM P741, P742, P743 All versions prior to B2A /li li Easergy MiCOM P746 All versions prior to B4E /li li Easergy MiCOM P746 All versions prior to C4E /li li Easergy MiCOM P849 All versions prior to B4A /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 5.3 /td td Schneider Electric /td td Schneider Electric Easergy MiCOM Px40 Series /td td Use of Hard-coded Credentials /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Energy, Transportation Systems /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong France /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-4832 /a /h3 div class="csaf-accordion-content" p CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-4832" View CVE Details /a /p hr h4 Affected Products /h4 h5 Schneider Electric Easergy MiCOM Px40 Series /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Schneider Electric /div div class="ics-version" strong Product

Sign in to read the full article

Create a free account to access all news, downloads, and community features

Originally published by CISA

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03

This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.

Shared on IT-Hub by admin