Executive Summary
In April 2026, Schneider Electric disclosed a vulnerability (CVE-2026-4832) in its Easergy MiCOM Px40 Series protection relays. The flaw involves hard-coded credentials within the SNMP interface, allowing unauthenticated attackers to access sensitive device information. Affected models include Easergy MiCOM P14x, P24x, P341, and others, with versions prior to specific firmware updates being vulnerable. The vulnerability has a CVSS v4.0 score of 6.9, indicating a medium severity level.
This incident underscores the critical importance of securing industrial control systems against unauthorized access. The use of hard-coded credentials is a known security risk, and organizations must prioritize updating firmware and implementing network protections to mitigate such vulnerabilities.
Why This Matters Now
The prevalence of hard-coded credentials in industrial devices poses significant security risks, especially as cyber threats targeting critical infrastructure continue to rise. Organizations must proactively address these vulnerabilities to prevent potential exploitation.
Attack Path Analysis
An attacker exploited hard-coded SNMP credentials in Schneider Electric Easergy MiCOM Px40 Series devices to gain unauthorized access to sensitive device information. This access could potentially be leveraged to escalate privileges, move laterally within the network, establish command and control channels, exfiltrate data, and impact system operations.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited hard-coded SNMP credentials to gain unauthorized access to the device's SNMP interface.
Related CVEs
CVE-2026-4832
CVSS 6.9A hard-coded credentials vulnerability in Schneider Electric Easergy MiCOM Px40 Series allows unauthenticated attackers to access sensitive device information via the SNMP port.
Affected Products:
Schneider Electric Easergy MiCOM P14x – All versions prior to B4A
Schneider Electric Easergy MiCOM P24x – All versions prior to D3A
Schneider Electric Easergy MiCOM P341 – All versions prior to E3F
Schneider Electric Easergy MiCOM P342, P343, P344, P345 – All versions prior to B3F
Schneider Electric Easergy MiCOM P442, P444 – All versions prior to E3A
Schneider Electric Easergy MiCOM P443, P445, P446, P543, P544, P545, P546 – All versions prior to H6A
Schneider Electric Easergy MiCOM P841 – All versions prior to G6A
Schneider Electric Easergy MiCOM P643 – All versions prior to B3F
Schneider Electric Easergy MiCOM P642, P645 – All versions prior to B4A
Schneider Electric Easergy MiCOM P741, P742, P743 – All versions prior to B2A
Schneider Electric Easergy MiCOM P746 – All versions prior to B4E or C4E
Schneider Electric Easergy MiCOM P849 – All versions prior to B4A
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Unsecured Credentials: Credentials in Files
Modify Authentication Process: Domain Controller Authentication
Application Layer Protocol: Web Protocols
Network Sniffing
Remote Services: SMB/Windows Admin Shares
External Remote Services
Valid Accounts: Local Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Authenticator Management
Control ID: IA-5
PCI DSS 4.0 – Secure Authentication Features
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: Identity Pillar
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical exposure through Schneider Electric protection relays in power grid infrastructure, enabling unauthorized device access via hardcoded SNMP credentials vulnerability.
Oil/Energy/Solar/Greentech
High-voltage protection systems compromised by CVE-2026-4832, exposing energy generation and distribution facilities to unauthorized reconnaissance and potential operational disruption.
Industrial Automation
Medium and high voltage protection relay vulnerabilities create attack vectors for industrial control system compromise through unencrypted SNMP protocol exploitation.
Transportation
Railway and transit power distribution systems using MiCOM protection relays vulnerable to device identification exposure through hardcoded credential exploitation.
Sources
- Schneider Electric Easergy MiCOM Px40 Serieshttps://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03Verified
- NVD - CVE-2026-4832https://nvd.nist.gov/vuln/detail/CVE-2026-4832Verified
- SEVD-2026-104-03 Use of Hard-coded Credentials vulnerability on Easergy MiCOM Px40 Serieshttps://www.se.com/us/en/download/document/SEVD-2026-104-03/Verified
- Security notifications | Schneider Electrichttps://www.se.com/ww/en/work/support/cybersecurity/security-notifications/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent initial unauthorized access due to hard-coded credentials, it would likely limit the attacker's ability to exploit this access to reach other network segments.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by restricting access to sensitive configurations and credentials.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict controls over internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict egress policies.
While Aviatrix CNSF may not prevent initial disruptions, it would likely limit the overall impact by containing the attacker's reach and preventing further spread within the network.
Impact at a Glance
Affected Business Functions
- Protection Relay Operations
- Grid Automation
Estimated downtime: N/A
Estimated loss: N/A
Potential unauthorized access to device identification information via SNMP.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized access to critical devices.
- • Enforce East-West Traffic Security to monitor and control lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network traffic and detect anomalies.
- • Apply Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and command and control communications.



