Junglewise Threat Intelligence

CVE-2026-6332: Schneider Electric EcoStruxure Machine Expert HVAC cleartext storage

CVE-2026-6332 · Severity: high · CVSS 7.5 · Published 2026-05-14

Vendors: Schneider Electric.

Executive brief

Schneider Electric EcoStruxure Machine Expert HVAC is a programming tool used to configure industrial logic controllers for heating, ventilation, and air conditioning systems. A vulnerability in this software allows sensitive information, including protected source code, to be stored in plain text. If an unauthorized user gains local access to the system, they could view this sensitive data, potentially leading to the theft of intellectual property or further exploitation of the industrial control environment.

Technical details

A cleartext storage of sensitive information vulnerability (CWE-312) exists in Schneider Electric EcoStruxure Machine Expert HVAC versions prior to 1.10.0. The flaw occurs when the software stores sensitive data, such as protected source code, in an unencrypted format on the local file system. An authorized local attacker can exploit this by accessing the source code files during editing or compilation processes. Successful exploitation results in a loss of confidentiality regarding proprietary logic and source code used in Modicon M171-M172 logic controllers. The issue is resolved in version 1.10.0.

Affected products

  • Schneider Electric EcoStruxure Machine Expert HVAC prior to 1.10.0

Timeline

  • 2026-05-20: disclosed
  • 2026-05-28: advisory: CISA Advisory ICSA-26-148-07 published
  • 2026-05-28: patched: Version 1.10.0 released

References