Junglewise Threat Intelligence

CVE-2026-9716: Schneider Electric PowerLogic P7 NULL pointer dereference DoS

CVE-2026-9716 · Severity: info · CVSS 8.7 · Published 2026-06-25

Technologies: Schneider Electric PowerLogic P7. Vendors: Schneider Electric.

Executive brief

A vulnerability in Schneider Electric PowerLogic P7 protection relays could allow an attacker to disable the device's management interface. These devices are critical components used in electrical power systems for monitoring and protection. If exploited, operators would lose the ability to configure the device or view status information through the Human Machine Interface (HMI), potentially impacting the reliability of power grid operations.

Technical details

A CWE-476 NULL Pointer Dereference vulnerability exists in Schneider Electric PowerLogic P7 devices (Version V02.003.001.000 and prior). The flaw is triggered when the device receives malformed requests over exposed network interfaces. An unauthenticated remote attacker can exploit this to cause a denial-of-service (DoS) condition, specifically rendering the Human Machine Interface (HMI) and configuration functionality unavailable. The vulnerability has a CVSS 4.0 base score of 8.7, reflecting high availability impact. Remediation details are typically found in Schneider Electric's security notice SEVD-2026-160-03.

Affected products

  • Schneider Electric PowerLogic™ P7 Version V02.003.001.000 and prior

Timeline

  • 2026-06-25: disclosed: Initial disclosure by Schneider Electric and NVD publication.

References

Related threats