Schneider Electric Easergy MiCOM Px40 Series - Hard-coded SNMP Credentials (CVE-2026-4832)
First seen Jul 10, 2026 · Updated Jul 10, 2026 · CVSS 5.3
Schneider Electric's Easergy MiCOM Px40 Series protection relays contain hard-coded credentials (CWE-798) exposed via the SNMP protocol, allowing an unauthenticated remote attacker to access basic device identification information. The vulnerability affects a wide range of firmware versions across nearly all Px40 relay models used in medium, high, and extra high voltage protection applications worldwide.
Technical Analysis
CVE-2026-4832 is a CWE-798 Use of Hard-coded Credentials vulnerability in the SNMP implementation of Schneider Electric Easergy MiCOM Px40 series relays, allowing an unauthenticated attacker who can reach the SNMP port to retrieve basic device identification data. The vulnerability has a CVSS v3.1 score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), reflecting low-complexity, network-based, unauthenticated access limited to confidentiality impact with no integrity or availability loss. This is an OT/ICS-specific hardware advisory affecting embedded protection relay firmware rather than IT infrastructure, and exploitation requires network reachability to the SNMP service, which is typically restricted in well-segmented industrial environments. There is no direct or plausible impact to AI agent systems, LLM tool use, or RAG pipelines, as this vulnerability is confined to industrial protection relay hardware/firmware and does not involve software components, credentials, or APIs used by AI agent frameworks.
Affected Systems
Easergy MiCOM P14x (prior to B4A), P24x (prior to D3A), P341 (prior to E3F), P342/P343/P344/P345 (prior to B3F), P442/P444 (prior to E3A), P443/P445/P446/P543/P544/P545/P546 (prior to H6A), P841 (prior to G6A), P643 (prior to B3F), P642/P645 (prior to B4A), P741/P742/P743 (prior to B2A), P746 (prior to B4E and C4E), P849 (prior to B4A)
Indicators of Compromise
- N/A - no known indicators of compromise; this is a vulnerability disclosure, not an active exploitation campaign
Remediation Steps
- 1
Disable SNMP if not required
Contact Schneider Electric's Customer Care Center to upgrade firmware to a version without SNMP functionality if SNMP is not needed.
- 2
Network isolation
Operate relays only within a protected network environment, isolated from business and untrusted networks.
- 3
Firewall segmentation
Use firewalls to separate control system networks from other networks and restrict access to the SNMP port.
- 4
Secure remote access
Use VPN tunnels for any required remote access, keeping VPN software updated to the latest secure version.
- 5
Apply firmware updates
Upgrade affected devices to the fixed firmware versions specified by Schneider Electric for each product line.
- 6
Follow ICS best practices
Implement defense-in-depth strategies per CISA and Schneider Electric recommended cybersecurity best practices, including minimizing internet exposure of control system devices.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.