CVE-2026-4832

MEDIUM

Schneider Electric Easergy MiCOM P14x <B4A - Info Disclosure

Title source: llm
STIX 2.1

Description

CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.

Scores

CVSS v4 6.9
EPSS 0.0008
EPSS Percentile 23.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (12)
Schneider Electric/Easergy MiCOM P14x All versions prior to B4A
Schneider Electric/Easergy MiCOM P24x All versions prior to D3A
Schneider Electric/Easergy MiCOM P341 All versions prior to E3F
Schneider Electric/Easergy MiCOM P342, P343, P344, P345 All versions prior to B3F
Schneider Electric/Easergy MiCOM P442, P444 All versions prior to E3A
Schneider Electric/Easergy MiCOM P443, P445, P446, P543, P544, P545, P546 All versions prior to H6A
Schneider Electric/Easergy MiCOM P642, P645 All versions prior to B4A
Schneider Electric/Easergy MiCOM P643 All versions prior to B3F
Schneider Electric/Easergy MiCOM P741, P742, P743 All versions prior to B2A
Schneider Electric/Easergy MiCOM P746 All versions prior to B4E or C4E
... and 2 more
Published Apr 14, 2026
Tracked Since Apr 14, 2026