« Volver al listado

CVE-2026-4827

Estado: Pendiente de análisisAlta (8.7)—

CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R con AV:N sugiere interacción del usuario (T1203). CWE-331 (insuficiente entropía) en gestión de sesiones permite acceso no autorizado, impactando en T1078 (obtención de credenciales/cuentas).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-4827",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-4827",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-12T12:39:02.210471Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cybersecurity@se.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "PASSIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@se.com",
      "affectedData": [
        {
          "vendor": "Schneider Electric",
          "product": "Easergy MiCOM C264",
          "versions": [
            {
              "status": "affected",
              "version": "Versions D6.x"
            },
            {
              "status": "affected",
              "version": "Versions D7.33 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "Easergy C5",
          "versions": [
            {
              "status": "affected",
              "version": "Version 1.1.17 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "Easergy MiCOM P30",
          "versions": [
            {
              "status": "affected",
              "version": "P139 version prior to P139.678.700"
            },
            {
              "status": "affected",
              "version": "P437 version prior to P437.678.700"
            },
            {
              "status": "affected",
              "version": "P439 version prior to P439.678.700"
            },
            {
              "status": "affected",
              "version": "P532 version prior to P532.678.700"
            },
            {
              "status": "affected",
              "version": "P539 version prior to P539.678.700"
            },
            {
              "status": "affected",
              "version": "P631 version prior to P631.678.700"
            },
            {
              "status": "affected",
              "version": "P632 version prior to P632.678.700"
            },
            {
              "status": "affected",
              "version": "P633 version prior to P633.678.700"
            },
            {
              "status": "affected",
              "version": "P634 version prior to P634.678.700"
            },
            {
              "status": "affected",
              "version": "P633 version P633.680.700 only"
            },
            {
              "status": "affected",
              "version": "P634 version P634.680.700 only"
            },
            {
              "status": "affected",
              "version": "P138 version prior to P138.677.700"
            },
            {
              "status": "affected",
              "version": "P436 version prior to P436.677.701"
            },
            {
              "status": "affected",
              "version": "P438 version prior to P438.677.701"
            },
            {
              "status": "affected",
              "version": "P638 version prior to P638.677.700"
            },
            {
              "status": "affected",
              "version": "C434 version prior to C434.679.700"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "Easergy MiCOM P40",
          "versions": [
            {
              "status": "affected",
              "version": "Series model numbers with Protocol Option bit as G, H or L and all firmware versions"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure™ Power Automation System Gateway (EPAS-GTW)",
          "versions": [
            {
              "status": "affected",
              "version": "Version 6.4.616.200.100 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure™ Power Automation System User Interface (EPAS-UI)",
          "versions": [
            {
              "status": "affected",
              "version": "Version 3.0.3 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure™ Power Operation",
          "versions": [
            {
              "status": "affected",
              "version": "Version 2022 CU6 and prior"
            },
            {
              "status": "affected",
              "version": "Version 2024 CU2 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "iPMFLS",
          "versions": [
            {
              "status": "affected",
              "version": "Version 64.2025.0.13 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "PowerLogic™ P5 Protection Relay",
          "versions": [
            {
              "status": "affected",
              "version": "V02.502.103 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "PowerLogic™ P7 Protection and Control Platform",
          "versions": [
            {
              "status": "affected",
              "version": "V02.002.002 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "PowerLogic™ T300",
          "versions": [
            {
              "status": "affected",
              "version": "Version 2.9.4 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "PowerLogic™ T500",
          "versions": [
            {
              "status": "affected",
              "version": "Version 11.08.02 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "Saitel DP",
          "versions": [
            {
              "status": "affected",
              "version": "Version 11.06.36 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EasyLogic T150 (formerly Saitel DR)",
          "versions": [
            {
              "status": "affected",
              "version": "Version 11.06.30 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-12T13:17:35.510",
  "references": [
    {
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-132-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-132-02.pdf",
      "source": "cybersecurity@se.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@se.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-331"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections."
    }
  ],
  "lastModified": "2026-06-17T10:57:17.890",
  "sourceIdentifier": "cybersecurity@se.com"
}