Siemens LOGO! Soft Comfort Software Has Encryption Flaws — Update Now
Siemens has disclosed two vulnerabilities affecting its LOGO! Soft Comfort software, used to program small industrial controllers. The issues stem from weak encryption and password handling: the software uses a hard-coded cryptographic key and stores password hashes without adding random data (a 'salt') to strengthen them.
A local attacker who gains access to project files could exploit the hard-coded key to extract the master key and decrypt sensitive project data or strip passwords entirely. The lack of salting also makes it easier for attackers to use offline brute-force or dictionary attacks to guess passwords. Together, these weaknesses could allow unauthorized access to, or tampering with, industrial control logic and configurations.
The vulnerabilities affect all versions of LOGO! Soft Comfort prior to version 9 and carry a moderate CVSS score of 6.8, requiring local access to exploit. Siemens has released an updated version that addresses both issues and recommends all users upgrade immediately.