CVE-2026-9716 Details
Description
CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces.
A NULL pointer dereference vulnerability has been identified in Schneider Electric's PowerLogic P7 protection and control platform, specifically in versions through V02.003.001.000. This vulnerability can cause a denial-of-service condition by rendering the device's human-machine interface (HMI) and configuration functionality unavailable. The issue arises when malformed requests are received over exposed network interfaces.
Users can upgrade to PowerLogic P7 version V02.004.001.000, which includes a fix for this vulnerability. This version is available through the Schneider Electric Customer Care Center. After updating, a reboot is required. If the update is not applied, it is recommended to restrict network access to the PowerLogic P7 service endpoints on TCP/IP port 8080 and to limit administrative access by applying least privilege principles.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-03.pdf | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| schneider-electric powerlogic p7 firmware | < 02.004.001.000 |
CPE
Remediation
| |
| schneider-electric powerlogic p7 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |