Status: UPDATED | Advisory ID: CVE-2026-9716
| CVE | CVE-2026-9716 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-07-01 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | Schneider Electric powerlogic_p7_firmware and Schneider Electric PowerLogic™ P7 |
| Classified as | CWE-476 (NULL Pointer Dereference) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Schneider Electric | powerlogic_p7_firmware | ||
| Schneider Electric | PowerLogic™ P7 |
| Subsystems | General OT |
| Sectors | Multiple |
CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces.
Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.