news.mlab.sh
Back to the feed
vulnerability

Schnieider Electric EcoStruxure Machine Expert HVAC (SEVD-2026-132-01)

High
Summary

This CISA advisory details a vulnerability (SEVD-2026-132-01) in Schneider Electric’s Ecostruxure Machine Expert HVAC software, specifically versions prior to 1.10.0. The vulnerability, classified as CWE-312 (Cleartext Storage of Sensitive Information), allows an attacker to potentially disclose protected source code, leading to confidentiality loss. Schneider Electric has released a fix in version 1.10.0, and the advisory recommends implementing security best practices to mitigate the risk.

Schneider Electric has identified a vulnerability within its Ecostruxure Machine Expert HVAC software, a programming tool used for Modicon M171-M172 logic controllers. The vulnerability, designated SEVD-2026-132-01, is classified as a Cleartext Storage of Sensitive Information (CWE-312) issue. This means that unauthorized access to the software could expose protected source code, compromising the confidentiality of the system. The advisory highlights the potential impact on critical infrastructure systems, particularly within the Chemical, Critical Manufacturing, Energy, and Water & Wastewater sectors. Schneider Electric recommends immediate action to address this vulnerability.

Read the full article at CISA Advisories