Our takeSiemens LOGO! Soft Comfort: flaws in project-file encryption let a local attacker extract the master key and brute-force unsalted password hashes offline. Treat project files as sensitive — LOGO! runs plenty of small automation shops. Check Siemens' advisory for fixes.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Update Siemens LOGO! Soft Comfort to the latest version per the CISA advisory; the flaws allow local attackers to extract the master key and decrypt projects or brute-force passwords.
What this means for you — Lean IT orgs:If you use Siemens LOGO! Soft Comfort on any computer, install the newest version right away. Most teams without this software can ignore it.
What this means for you — MSP:Check client environments for Siemens LOGO! Soft Comfort deployments and push the vendor update; the encryption and password-handling flaws let a local user recover the master key and decrypt or crack project files.
What this means for you — Researcher:CISA advisory ICSA-26-225-13 details multiple flaws in Siemens LOGO! Soft Comfort project-file encryption and unsalted password storage that let a local attacker extract the master key.