CVE-2026-6332

HIGH

View CSAF Summary Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document...

Affects 0 products across 2 vendors.

BCS3.51
CVSS 3.17.5
CVSS v46.8
EPSS0.1%
Percentile3th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-312: CWE-312
Related Attack Patterns (CAPEC)
CAPEC-37 Retrieve Embedded Sensitive Data
via CWE-312

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A CWE-312 vulnerability (Cleartext Storage of Sensitive Information) exists, potentially leading to the disclosure of sensitive information, including protected source code, resulting in a loss of confidentiality.

BSID: BS-2026-GLOBAL-154366-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-6332?
A CWE-312 vulnerability (Cleartext Storage of Sensitive Information) exists, potentially leading to the disclosure of sensitive information, including protected source code, resulting in a loss of confidentiality.
What is the CVSS score for CVE-2026-6332?
CVE-2026-6332 has CVSS 7.5 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. EPSS: 0.1%.
Is CVE-2026-6332 actively exploited?
No confirmed active exploitation of CVE-2026-6332 as of 2026-05-30.
How do I remediate CVE-2026-6332?
Priority: HIGH.
What systems are affected by CVE-2026-6332?
CVE-2026-6332 affects: Schneider-Electric, Wolfram Schneider.
Vulnerability Details
CVE IDCVE-2026-6332
BSIDBS-2026-GLOBAL-154366-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published2026-05-28
Last Modified2026-05-28
ICS Relevance65%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document/EcoStruxureME_HVAC/) product is a programming software for Modicon M171-M172 logic controllers. Failure to apply the remediation provided below may risk in revealing sensitive information, which could result in disclosing protected source code, leading to loss of confidentiality. The following version

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An authorized attacker could access the source code for editing or compiling, exploiting the fact that sensitive information is stored in cleartext, leading to unauthorized disclosure.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Schneider-Electric —
Wolfram Schneider —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 58 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
Related CVEs affecting Schneider-Electric
CVE-2011-4861 10.0 The modbus_125_handler function in the Schneider Electric Quantum Ethernet Mo... CVE-2013-0657 10.0 Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA... CVE-2020-11897 10.0 The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multipl... CVE-2020-11896 10.0 The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related ... CVE-2013-3075 10.0 Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3...
View all Schneider-Electric CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →