CVE-2026-4827

HIGH

Schneider Electric Easergy MiCOM C264 - Insufficient Entropy Vulnerability on Multiple Products

Title source: rule
STIX 2.1

Description

CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.

Scores

CVSS v4 8.7
EPSS 0.0031
EPSS Percentile 22.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-331
Status published
Products (50)
Schneider Electric/Easergy C5 Version 1.1.17 and prior
Schneider Electric/Easergy MiCOM C264 Versions D6.x
Schneider Electric/Easergy MiCOM C264 Versions D6.x all versions
Schneider Electric/Easergy MiCOM C264 Versions D7.33 and prior
Schneider Electric/Easergy MiCOM P30 C434 version prior to C434.679.700
Schneider Electric/Easergy MiCOM P30 Easergy MiCOM C434 version prior to C434.679.700
Schneider Electric/Easergy MiCOM P30 Easergy MiCOM P138 version prior to P138.677.700
Schneider Electric/Easergy MiCOM P30 Easergy MiCOM P139 version prior to P139.678.700
Schneider Electric/Easergy MiCOM P30 Easergy MiCOM P436 version prior to P436.677.701
Schneider Electric/Easergy MiCOM P30 Easergy MiCOM P437 version prior to P437.678.700
... and 40 more
Published May 12, 2026
Tracked Since May 12, 2026