Insufficient Entropy vulnerability on Multiple Products

Summary

CVECVE-2026-4827
StatePUBLISHED
Assignerschneider
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-05-12 13:17:35 UTC
Updated2026-05-14 18:16:50 UTC
DescriptionCWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.

Risk And Classification

Primary CVSS: v4.0 8.7 HIGH from [email protected]

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS: 0.000660000 probability, percentile 0.203910000 (date 2026-05-25)

Problem Types: CWE-331 | CWE-331 CWE-331 Insufficient entropy


VersionSourceTypeScoreSeverityVector
4.0[email protected]Secondary8.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/C...
4.0CNACVSS8.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

CVSS v4.0 Breakdown

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Passive
Confidentiality
High
Integrity
High
Availability
Low
Sub Conf.
None
Sub Integrity
None
Sub Availability
None

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Schneider Electric Easergy MiCOM C264 affected Versions D6.x Not specified
CNA Schneider Electric Easergy MiCOM C264 affected Versions D7.33 and prior Not specified
CNA Schneider Electric Easergy C5 affected Version 1.1.17 and prior Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P139 version prior to P139.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P437 version prior to P437.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P439 version prior to P439.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P532 version prior to P532.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P539 version prior to P539.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P631 version prior to P631.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P632 version prior to P632.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P633 version prior to P633.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P634 version prior to P634.678.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P633 version P633.680.700 only Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P634 version P634.680.700 only Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P138 version prior to P138.677.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P436 version prior to P436.677.701 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P438 version prior to P438.677.701 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected P638 version prior to P638.677.700 Not specified
CNA Schneider Electric Easergy MiCOM P30 affected C434 version prior to C434.679.700 Not specified
CNA Schneider Electric Easergy MiCOM P40 affected Series model numbers with Protocol Option bit as G, H or L and all firmware versions Not specified
CNA Schneider Electric EcoStruxure Power Automation System Gateway EPAS-GTW affected Version 6.4.616.200.100 and prior Not specified
CNA Schneider Electric EcoStruxure Power Automation System User Interface EPAS-UI affected Version 3.0.3 and prior Not specified
CNA Schneider Electric EcoStruxure Power Operation affected Version 2022 CU6 and prior Not specified
CNA Schneider Electric EcoStruxure Power Operation affected Version 2024 CU2 and prior Not specified
CNA Schneider Electric IPMFLS affected Version 64.2025.0.13 and prior Not specified
CNA Schneider Electric PowerLogic P5 Protection Relay affected V02.502.103 and prior Not specified
CNA Schneider Electric PowerLogic P7 Protection And Control Platform affected V02.002.002 and prior Not specified
CNA Schneider Electric PowerLogic T300 affected Version 2.9.4 and prior Not specified
CNA Schneider Electric PowerLogic T500 affected Version 11.08.02 and prior Not specified
CNA Schneider Electric Saitel DP affected Version 11.06.36 and prior Not specified
CNA Schneider Electric EasyLogic T150 Formerly Saitel DR affected Version 11.06.30 and prior Not specified

References

ReferenceSourceLinkTags
download.schneider-electric.com/files [email protected] download.schneider-electric.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report