VORANT. Threat Intelligence Sign in Get the full feed

Schneider Electric patched a cleartext storage flaw in EcoStruxure Machine Expert HVAC…

medium vulnerability energyinfrastructuremanufacturing

Schneider Electric patched a cleartext storage flaw in EcoStruxure Machine Expert HVAC that exposes protected source code to authorized attackers.

Schneider Electric disclosed CVE-2026-6332, a cleartext storage vulnerability (CWE-312) in EcoStruxure Machine Expert HVAC, a programming platform for Modicon M171/M172 logic controllers used in industrial environments. The flaw allows an authorized attacker with access to source code during editing or compilation to extract sensitive information, including protected intellectual property, resulting in loss of confidentiality. All versions prior to 1.10.0 are affected.

The vulnerability was reported by Schneider Electric's own CPCERT team to CISA. While the issue requires existing authorized access, the exposure of proprietary controller logic poses risks to facilities across chemical, critical manufacturing, energy, and water sectors worldwide. Schneider Electric released version 1.10.0 to remediate the issue.

No evidence of active exploitation is mentioned in the advisory. Organizations using affected versions should upgrade to 1.10.0 immediately and follow defense-in-depth practices, including network segmentation, physical access controls for programming terminals, and restricting programming software to isolated networks.

Mentioned in this report

Vulnerabilities CVE-2026-6332

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-07

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free