As cited
Copy frozen at (site build).
vulnerabilities
Siemens LOGO! Soft Comfort
Siemens LOGO! Soft Comfort versions before V9 contain two cryptographic vulnerabilities: a hardcoded AES master key that allows local attackers to decrypt project files, and unsalted SHA-256 password hashes that enable offline dictionary attacks. Siemens has released version V9 with fixes, though a hardware upgrade to LOGO! V9 BM or later is also required to fully remediate the vulnerabilities.
Why it matters: Organizations deploying LOGO! Soft Comfort for industrial control systems must update to V9 and upgrade compatible hardware to prevent local attackers from extracting sensitive project logic, configurations, and removing password protections.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Siemens LOGO! Soft Comfort
Siemens LOGO! Soft Comfort versions before V9 contain two cryptographic vulnerabilities: CVE-2026-57262 uses a hardcoded AES master key to encrypt project files, and CVE-2026-57263 stores project passwords as unsalted SHA-256 hashes. A local attacker could extract the master key or perform offline dictionary attacks to decrypt projects or remove password protections. Siemens recommends updating to version V9 or later and notes that a hardware upgrade to LOGO! V9 BM or later is required to fully remediate the issues.
Why it matters: Organizations deploying LOGO! Soft Comfort in industrial control systems or commercial facilities should prioritize updating to V9, as local attackers with access to affected systems can decrypt sensitive project logic and configurations without the original password.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Siemens LOGO! Soft Comfort
Siemens LOGO! Soft Comfort versions before V9 contain two cryptographic vulnerabilities: CVE-2026-57262 uses a hardcoded AES master key to encrypt project files, and CVE-2026-57263 stores project passwords as unsalted SHA-256 hashes. A local attacker could extract the master key or perform offline dictionary attacks to decrypt projects or remove password protections. Siemens recommends updating to version V9 or later and notes that a hardware upgrade to LOGO! V9 BM or later is required to fully remediate the issues.
Why it matters: Organizations deploying LOGO! Soft Comfort in industrial control systems or commercial facilities should prioritize updating to V9, as local attackers with access to affected systems can decrypt sensitive project logic and configurations without the original password.
- Source published
- First seen by Cybersecurity Tracker