CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Schneider Electric | Easergy C5 | Version 1.1.17 and priorCNA affecteddefault unaffected | |
| Schneider Electric | Easergy MiCOM C264 | Versions D6.x, Versions D7.33 and priorCNA affecteddefault unaffected | |
| Schneider Electric | Easergy MiCOM P30 | C434 version prior to C434.679.700, P138 version prior to P138.677.700, P139 version prior to P139.678.700, P436 version prior to P436.677.701, P437 version prior to P437.678.700, P438 version prior to P438.677.701, P439 version prior to P439.678.700, P532 version prior to P532.678.700, P539 version prior to P539.678.700, P631 version prior to P631.678.700, P632 version prior to P632.678.700, P633 version P633.680.700 only, P633 version prior to P633.678.700, P634 version P634.680.700 only, P634 version prior to P634.678.700, P638 version prior to P638.677.700CNA affecteddefault unaffected | |
| Schneider Electric | Easergy MiCOM P40 | Series model numbers with Protocol Option bit as G, H or L and all firmware versionsCNA affecteddefault unaffected | |
| Schneider Electric | EasyLogic T150 (Formerly Saitel DR) | Version 11.06.30 and priorCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.