Siemens LOGO! Soft Comfort
Brief
View CSAF
Summary
Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes.
Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.
The following versions of Siemens LOGO! Soft Comfort are affected:
- LOGO! Soft Comfort vers:intdot/
