Government Advisory

Siemens LOGO! Soft Comfort Software Has Encryption Flaws — Update Now

CISA · 13 Aug 2026
Key Takeaway If your business uses Siemens LOGO! Soft Comfort for industrial control programming, update to the latest version now to close these encryption and password weaknesses.

Siemens has disclosed two vulnerabilities affecting its LOGO! Soft Comfort software, used to program small industrial controllers. The issues stem from weak encryption and password handling: the software uses a hard-coded cryptographic key and stores password hashes without adding random data (a 'salt') to strengthen them.

A local attacker who gains access to project files could exploit the hard-coded key to extract the master key and decrypt sensitive project data or strip passwords entirely. The lack of salting also makes it easier for attackers to use offline brute-force or dictionary attacks to guess passwords. Together, these weaknesses could allow unauthorized access to, or tampering with, industrial control logic and configurations.

The vulnerabilities affect all versions of LOGO! Soft Comfort prior to version 9 and carry a moderate CVSS score of 6.8, requiring local access to exploit. Siemens has released an updated version that addresses both issues and recommends all users upgrade immediately.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.