Schnieider Electric EcoStruxure Machine Expert HVAC
CISA says Schneider Electric fixed a medium-severity flaw in EcoStruxure Machine Expert HVAC that could expose sensitive source code.
Intelligence analysis by GPT-5.4 Mini
CISA published an ICS advisory for a Schneider Electric flaw in EcoStruxure Machine Expert HVAC. The issue affects versions before 1.10.0 and can expose sensitive information, including protected source code, if an authorized attacker edits or compiles it.
A tool that helps run factory machines had a weak spot. Because of that weak spot, someone with the right access could see secret code that should have stayed hidden.
It is like leaving a notebook with important instructions on a table instead of in a drawer. If the wrong person reads it, they may learn how things work and use that knowledge badly.
The fix is to update to version 1.10.0. CISA also tells companies to keep these machine systems separated from regular office networks and to be careful with remote access and USB drives.
Analysis
What CISA reported
CISA says Schneider Electric is aware of a vulnerability in its EcoStruxure Machine Expert HVAC software, which is used to program Modicon M171-M172 logic controllers. The advisory says the flaw could reveal sensitive information and lead to loss of confidentiality if an authorized attacker accesses source code for editing or compiling.
Scope and severity
The affected product versions are those prior to 1.10.0. CISA lists the issue as CVE-2026-6332, tracked by Schneider Electric as SEVD-2026-132-01, with a CVSS v3.1 base score of 5.5 and a medium severity rating. The weakness is classified as CWE-312, cleartext storage of sensitive information.
Remediation and operational guidance
Schneider Electric says version 1.10.0 includes the fix and is available for download. CISA also repeats standard industrial control system security guidance: keep control networks isolated from business networks, restrict physical access, avoid connecting programming tools to the wrong network, scan removable media before use, minimize internet exposure, and use secure remote access methods such as VPNs with current updates.
The advisory notes that the affected software is used in critical infrastructure contexts, including chemical, critical manufacturing, energy, and water and wastewater sectors. The exposure is worldwide, and CISA directs users to Schneider Electric support channels for more help.
Key points
- CISA issued an advisory for Schneider Electric EcoStruxure Machine Expert HVAC.
- Versions prior to 1.10.0 are affected.
- The flaw can expose sensitive information, including protected source code.
- The issue is tracked as CVE-2026-6332 and rated CVSS 5.5 medium.
- Schneider Electric says version 1.10.0 fixes the problem.



