Schneider Electric EcoStruxure Machine Expert HVAC
cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*, +1 more
- < 1.10.0
A vulnerability allowing cleartext storage of sensitive information has been identified in Schneider Electric's EcoStruxure Machine Expert HVAC software, prior to version 1.10.0. This vulnerability could lead to the unauthorized disclosure of protected source code, allowing an authorized attacker to access the source code for editing or compilation, thereby compromising confidentiality.
Exploitation of this vulnerability could result in the unauthorized disclosure of protected source code, leading to a loss of confidentiality.
Users of EcoStruxure Machine Expert HVAC should upgrade to version 1.10.0, which includes a fix for this vulnerability. Version 1.10.0 is available for download from the Schneider Electric website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.