← All Advisories

CVE-2026-6332

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-6332

Key Details

CVECVE-2026-6332
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsSchneider Electric ecostruxure_machine_expert_hvac and Schneider Electric Ecostruxure™ Machine Expert HVAC
Classified asCWE-312 (Cleartext Storage of Sensitive Information)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Schneider Electricecostruxure_machine_expert_hvac
Schneider ElectricEcostruxure™ Machine Expert HVAC
SubsystemsGeneral OT
SectorsMultiple

What to Know

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.

What to Do

Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6332
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-6332
Vendor advisoryhttps://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-132-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-132-01.pdf