Hard-Coded Credentials Expose Schneider Electric Protection Relays to Unauthorized Access
The Schneider Electric Easergy MiCOM Px40 Series vulnerability highlights a critical failure in secure-by-design principles: hard-coded credentials embedded in operational technology (OT) firmware give attackers a permanent, unchangeable foothold that no password policy can fix. Because these relays operate over SNMP — a protocol known for weak authentication — unauthenticated attackers on the same network can silently enumerate device information without triggering obvious alarms. This matters because protection relays are safety-critical components in electrical infrastructure; even reconnaissance-level access can inform more destructive follow-on attacks. The widespread version range affected suggests the flaw was baked in during development and propagated across an entire product family, amplifying the blast radius significantly.
Tactical Insight
Immediate actions
- Isolate all affected Easergy MiCOM Px40 Series relays behind dedicated OT network segments or firewalls to block unsolicited SNMP traffic.
- Apply the vendor-supplied firmware upgrade that disables SNMP or upgrades to authenticated SNMP v3 as soon as operationally feasible.
- Conduct an emergency audit of all SNMP-enabled OT and ICS devices to identify any others using default or hard-coded community strings.
Long-term improvements
- Enforce a secure product development lifecycle (SDLC) requirement that prohibits hard-coded credentials in any firmware or embedded software.
- Maintain a continuously updated OT/ICS asset inventory with firmware versions to accelerate future vulnerability scoping and patching.
- Require VPN or encrypted out-of-band channels for all remote access to operational technology assets.
Detection measures
- Deploy OT-aware network monitoring (e.g., Claroty, Dragos, or Nozomi) to alert on anomalous SNMP polling or unexpected device enumeration activity.
- Establish baseline traffic profiles for protection relays and trigger alerts when SNMP queries originate from unauthorized source IPs.
- Integrate ICS vulnerability feeds into your SIEM so newly disclosed CVEs against deployed OT assets generate automatic triage tickets.