Home

Description

CWE‑331 Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.

PUBLISHED Reserved 2026-03-25 | Published 2026-05-12 | Updated 2026-05-12 | Assigner schneider




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-331 Insufficient entropy

Product status

Default status
unaffected

Versions D6.x all versions
affected

Versions D7.33 and prior
affected

Default status
unaffected

Version 1.1.17 and prior
affected

Default status
unaffected

Easergy MiCOM P139 version prior to P139.678.700
affected

Easergy MiCOM P437 version prior to P437.678.700
affected

Easergy MiCOM P439 version prior to P439.678.700
affected

Easergy MiCOM P532 version prior to P532.678.700
affected

Easergy MiCOM P539 version prior to P539.678.700
affected

Easergy MiCOM P631 version prior to P631.678.700
affected

Easergy MiCOM P632 version prior to P632.678.700
affected

Easergy MiCOM P633 version prior to P633.678.700
affected

Easergy MiCOM P633 version P633.680.700 only
affected

Easergy MiCOM P634 version prior to P634.678.700
affected

Easergy MiCOM P634 version P634.680.700 only
affected

Easergy MiCOM P138 version prior to P138.677.700
affected

Easergy MiCOM P436 version prior to P436.677.701
affected

Easergy MiCOM P438 version prior to P438.677.701
affected

Easergy MiCOM P638 version prior to P638.677.700
affected

Easergy MiCOM C434 version prior to C434.679.700
affected

Default status
unaffected

P_ 4_ _ _ _ _ G_ _ _ _ _ M
affected

P_ 4_ _ _ _ _ H_ _ _ _ _ M
affected

P_ 4_ _ _ _ _ L _ _ _ _ _ M
affected

P_ 4_ _ _ _ _ G_ _ _ _ _ L
affected

P_ 4_ _ _ _ _ H_ _ _ _ _ L
affected

P_ 4_ _ _ _ _ L _ _ _ _ _ L
affected

Default status
unaffected

Version 6.4.616.200.100 and prior
affected

Default status
unaffected

Version 3.0.3 and prior
affected

Default status
unaffected

Version 2022 CU6 and prior
affected

Version 2024 CU2 and prior
affected

Default status
unaffected

Version 64.2025.0.13 and prior
affected

Default status
unaffected

V02.502.103 and prior
affected

Default status
unaffected

V02.002.002 and prior
affected

Default status
unaffected

Version 2.9.4 and prior
affected

Default status
unaffected

Version 11.08.02 and prior
affected

Default status
unaffected

Version 11.06.36 and prior
affected

Default status
unaffected

Version 11.06.30 and prior
affected

References

download.schneider-electric.com/...Name=SEVD-2026-132-02.pdf

cve.org (CVE-2026-4827)

nvd.nist.gov (CVE-2026-4827)

Download JSON