CVE-2026-57262
6.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Summary
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Siemens | LOGO! Soft Comfort | 0 < V9 | affected |
Weaknesses
- CWE-321: CWE-321: Use of Hard-coded Cryptographic Key
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.