CVE-2026-6332

HIGH

Clear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVAC

Title source: cna
STIX 2.1

Description

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 2.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (2)
Schneider Electric/Ecostruxure™ Machine Expert HVAC Versions prior to 1.10.0
schneider-electric/ecostruxure_machine_expert_hvac < 1.10.0
Published May 14, 2026
Tracked Since May 14, 2026