CVE-2026-4827 Details
Description
CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.
A vulnerability exists in various Schneider Electric products due to insufficient entropy, which could lead to unauthorized access. This issue arises when an attacker on the network exploits weaknesses in session management protections. Affected products include the Easergy C5, Easergy MiCOM P30, Easergy MiCOM P40, Easergy MiCOM C264, EcoStruxure Power Automation System Gateway (EPAS-GTW), EcoStruxure Power Automation System User Interface (EPAS-UI), EcoStruxure Power Operation, PowerLogic P5, PowerLogic P7, PowerLogic T300, PowerLogic T500, Saitel DP, and EasyLogic T150, across several different versions and ranges.
Users can update to the latest versions of the affected products. For specific version details, refer to the Schneider Electric Security Notification SEVD-2026-132-02. After updating, a reboot is required to complete the process. If the update is not possible, apply recommended mitigations such as ensuring the device operates within a segmented internal network and reducing session timeout durations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-132-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-132-02.pdf | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-331 | Insufficient Entropy | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | New CVE Received | [email protected] |