Siemens LOGO! Soft Comfort Vulnerabilities Disclosed: Hardcoded Key and Weak Password Hashing
Siemens LOGO! Soft Comfort versions prior to V9 contain two vulnerabilities affecting project-file encryption and password handling. CVE-2026-57262 involves a static, hardcoded AES master key that could be extracted to decrypt project files or remove passwords without user authentication. CVE-2026-57263 involves the storage of project passwords as unsalted SHA-256 hashes, enabling efficient offline dictionary or brute-force attacks. Both vulnerabilities are rated CVSS 3.1 base score 6.8 (MEDIUM) and require local access. Siemens recommends updating to LOGO! Soft Comfort V9 or later, and notes that a hardware upgrade to LOGO! V9 BM or later is required to avoid compatibility mode where the vulnerabilities persist.