news.mlab.sh
Back to the feed
vulnerability

Siemens LOGO! Soft Comfort

High
Summary

Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling, allowing a local attacker to extract the master key and decrypt project data or remove passwords. These vulnerabilities stem from a hardcoded AES master key and unsalted SHA-256 password hashes, enabling dictionary and brute-force attacks. Updating to LOGO! Soft Comfort version V9 or later (along with a hardware upgrade) is critical to address these issues.

Read the full article at CISA Advisories

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.