CVE-2026-6332
View CSAF Summary Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document...
Affects 0 products across 2 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A CWE-312 vulnerability (Cleartext Storage of Sensitive Information) exists, potentially leading to the disclosure of sensitive information, including protected source code, resulting in a loss of confidentiality.
BSID: BS-2026-GLOBAL-154366-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-6332?
What is the CVSS score for CVE-2026-6332?
Is CVE-2026-6332 actively exploited?
How do I remediate CVE-2026-6332?
What systems are affected by CVE-2026-6332?
| CVE ID | CVE-2026-6332 |
|---|---|
| BSID | BS-2026-GLOBAL-154366-I BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Published | 2026-05-28 |
| Last Modified | 2026-05-28 |
| ICS Relevance | 65% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document/EcoStruxureME_HVAC/) product is a programming software for Modicon M171-M172 logic controllers. Failure to apply the remediation provided below may risk in revealing sensitive information, which could result in disclosing protected source code, leading to loss of confidentiality. The following version
Source: NIST NVD / MITRE CVE Database
An authorized attacker could access the source code for editing or compiling, exploiting the fact that sensitive information is stored in cleartext, leading to unauthorized disclosure.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Schneider-Electric | — | — |
| Wolfram Schneider | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →