Our takeCISA: Siemens LOGO! Soft Comfort has weak project-file crypto — a local attacker can extract the master key, decrypt project data, and brute-force unsalted password hashes offline. Treat project passwords as no real protection; restrict access to the files themselves.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Update Siemens LOGO! Soft Comfort to the latest version immediately if you use it for PLC programming. The CISA advisory details multiple flaws in project-file encryption and unsalted password hashing that let a local attacker extract the master key and decrypt projects.
What this means for you — Lean IT orgs:If you run Siemens LOGO! Soft Comfort on any computer, update it now using the latest version from Siemens. Most teams without this software can ignore this advisory.
What this means for you — MSP:Check client environments for Siemens LOGO! Soft Comfort installations and push the vendor update; the CISA-listed flaws allow local attackers to recover the master key and decrypt or unlock project files.
What this means for you — Researcher:CISA advisory ICSA-26-225-13 details flaws in Siemens LOGO! Soft Comfort project-file encryption and unsalted password storage that let local attackers extract the master key for offline brute-force or decryption.