CVE-2026-4832

MEDIUMCVSS 6.9/10EPSS 0.27%

Last modified

CVE-2026-4832 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.

Description

CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.

Metrics

CVSS 4.0
6.9/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.27%

18.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Schneider ElectricEasergy MiCOM P14xAll versions prior to B4A
Schneider ElectricEasergy MiCOM P24xAll versions prior to D3A
Schneider ElectricEasergy MiCOM P341All versions prior to E3F
Schneider ElectricEasergy MiCOM P342, P343, P344, P345All versions prior to B3F
Schneider ElectricEasergy MiCOM P442, P444All versions prior to E3A
Schneider ElectricEasergy MiCOM P443, P445, P446, P543, P544, P545, P546All versions prior to H6A
Schneider ElectricEasergy MiCOM P642, P645All versions prior to B4A
Schneider ElectricEasergy MiCOM P643All versions prior to B3F
Schneider ElectricEasergy MiCOM P741, P742, P743All versions prior to B2A
Schneider ElectricEasergy MiCOM P746All versions prior to B4E or C4E
Schneider ElectricEasergy MiCOM P841All versions prior to G6A
Schneider ElectricEasergy MiCOM P849All versions prior to B4A

References

Timeline

Published
Last Modified
Status
Undergoing Analysis

Frequently Asked Questions

What is CVE-2026-4832?
CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.
How severe is CVE-2026-4832?
CVE-2026-4832 has a CVSS score of 6.9/10 (MEDIUM severity). The EPSS model estimates a 0.27% probability of exploitation in the next 30 days.
How do I fix CVE-2026-4832?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-4832?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST