← Back to Feed

Siemens LOGO! Soft Comfort

CVE-2026-57262CVE-2026-57263

August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL

Siemens LOGO! Soft Comfort before V9 uses a hardcoded AES master key (CVE-2026-57262) and unsalted password hashes (CVE-2026-57263), allowing local attackers to decrypt project data or brute-force passwords. A hardware upgrade to LOGO! V9 BM or later is also required to fully resolve the vulnerabilities. Siemens recommends updating to version V9.

Key Takeaways

  • Static hardcoded AES master key enables decryption of project files and password removal.
  • Unsalted password hashes allow offline dictionary or brute-force attacks against user passwords.
  • Update to LOGO! Soft Comfort V9 and upgrade hardware to avoid compatibility mode.
☕ Buy a Coffee