Schneider Easergy MiCOM Px40 relays expose device data through SNMP
CVSS 5.3 understates the operational problem when the target is a protection relay deployed across voltage classes.
TL;DR
CISA published ICSA-26-190-03 for CVE-2026-4832, a CVSS 5.3 hard-coded credentials flaw in Schneider Electric Easergy MiCOM Px40 protection relays. Affected firmware spans Px40 models used in medium-, high- and extra-high-voltage systems worldwide, where unauthenticated attackers can interrogate the SNMP port for sensitive device information. Defense Industrial Base sites, municipal operators and contractors should upgrade firmware where SNMP is unnecessary, or isolate relays behind protected networks, firewalls and VPN-controlled remote access. The operational problem is fleet-level reconnaissance across voltage classes.
CISA’s advisory on Schneider Electric’s Easergy MiCOM Px40 Series is a medium-severity CVE with a grid-shaped blast radius. CVE-2026-4832 is a CWE-798 hard-coded credentials issue with a CVSS 3.1 score of 5.3. An unauthenticated attacker who can reach the SNMP port can obtain sensitive device information. Schneider describes the exposed material as basic device identification.
The affected list is broad: Px40 relays used for medium-, high- and extra-high-voltage protection, including P14x, P24x, P341, P342-P345, P442/P444, P443/P445/P446/P543-P546, P841, P643, P642/P645, P741-P743, P746 and P849 firmware below Schneider’s fixed versions. CISA lists worldwide deployment in Critical Manufacturing, Energy and Transportation Systems. That pushes the issue from a relay ticket into a fleet exposure-management task for utilities, Defense Industrial Base facilities, municipal operators and contractors.
CISA’s vector matters: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N means network reachable, low complexity, no privileges and no user interaction, with low confidentiality impact and no stated integrity or availability impact. The advisory describes information exposure; it does not say the credential permits configuration changes or relay manipulation. That boundary is useful, but reconnaissance of protection infrastructure is still useful to an attacker.
Monday work is blunt: inventory Px40 deployments, map model and firmware against Schneider’s cutoffs, remove SNMP functionality through the firmware path where SNMP is unnecessary, and otherwise isolate the relays in protected networks behind firewalls with VPN-only remote access. A CVSS 5.3 item should move faster when it names protection relays across voltage classes.
Published ·Deep Fathom