Status: UPDATED | Advisory ID: CVE-2026-6332
| CVE | CVE-2026-6332 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | Schneider Electric ecostruxure_machine_expert_hvac and Schneider Electric Ecostruxure™ Machine Expert HVAC |
| Classified as | CWE-312 (Cleartext Storage of Sensitive Information) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Schneider Electric | ecostruxure_machine_expert_hvac | ||
| Schneider Electric | Ecostruxure™ Machine Expert HVAC |
| Subsystems | General OT |
| Sectors | Multiple |
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.
Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.