CVE-2026-6332
published 2026-05-14CVE-2026-6332: CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.13%
2.6th percentile
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_machine_expert_hvac | < 1.10.0 | 1.10.0 |
| schneider_electric | ecostruxure_machine_expert_hvac | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Schneider Electric Ecostruxure Machine Expert HVAC up to 1.9.x cleartext storage (SEVD-2026-132-01)
vuldb·2026-05-14·CVSS 6.8
CVE-2026-6332 [MEDIUM] Schneider Electric Ecostruxure Machine Expert HVAC up to 1.9.x cleartext storage (SEVD-2026-132-01)
A vulnerability was found in Schneider Electric Ecostruxure Machine Expert HVAC up to 1.9.x. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is referenced as CVE-2026-6332. The attack can only be performed from a local environment. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-vg4w-v23f-w7r7: CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result
ghsa_unreviewed·2026-05-14
CVE-2026-6332 [MEDIUM] CWE-312 GHSA-vg4w-v23f-w7r7: CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-14
Published