CVE-2026-9718 Details
Description
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service.
A reachable assertion vulnerability has been identified in Schneider Electric's PowerLogic P7 protection and control platform, specifically in versions through V02.003.001.000. This vulnerability allows an authenticated attacker to trigger a denial-of-service condition by sending a specially crafted request to a network-exposed service, thereby impacting system availability.
Users can upgrade to PowerLogic P7 version V02.004.001.000, which includes a fix for this vulnerability. This version is available through the Schneider Electric Customer Care Center. After applying the patch, a reboot is required. If the patch cannot be applied, it is recommended to restrict network access to the PowerLogic P7 service endpoints on TCP/IP port 8080 and to limit administrative access by applying least privilege principles for all users interacting with PowerLogic P7.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-03.pdf | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| schneider-electric powerlogic p7 firmware | < 02.004.001.000 |
CPE
Remediation
| |
| schneider-electric powerlogic p7 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |