Hard-coded SNMP creds in Schneider MiCOM relays
Schneider Electric Easergy MiCOM Px40 protection relays use hard-coded SNMP credentials, letting unauthenticated attackers read basic device information.
CISA republished a Schneider Electric CPCERT advisory disclosing CVE-2026-4832, a hard-coded credentials vulnerability (CWE-798) affecting the Easergy MiCOM Px40 series of protection relays used in medium, high, and extra-high voltage grid automation. An unauthenticated attacker able to reach the SNMP port on an affected device could interrogate it and obtain basic device identification information.
The vulnerability spans nearly the entire Px40 product line, including P14x, P24x, P341-P345, P442-P446, P543-P546, P841, P643, P642/P645, P741-P743, P746, and P849 models across multiple firmware version ranges. These relays are deployed worldwide primarily in the Energy sector, with additional relevance to Critical Manufacturing and Transportation Systems. Schneider Electric is headquartered in France.
No public exploitation has been reported. Schneider recommends customers who do not need SNMP upgrade firmware to a version lacking SNMP functionality via the Customer Care Center. For all customers, standard ICS hardening is advised: isolate relays on protected networks, use firewalls to segment control networks from business networks, and require VPN tunneling for any remote access. The disclosure was reported to CISA by Schneider Electric's CPCERT team.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free