vulnerability
Siemens LOGO! Soft Comfort
High
Summary
Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling, allowing a local attacker to extract the master key and decrypt project data or remove passwords. These vulnerabilities stem from a hardcoded AES master key and unsalted SHA-256 password hashes, enabling dictionary and brute-force attacks. Updating to LOGO! Soft Comfort version V9 or later (along with a hardware upgrade) is critical to address these issues.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data