Man-in-the-Middle Vulnerability in Siemens LOGO! Soft Comfort Software
CVE-2017-12740
5.9MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 26 December 2017
Summary
Siemens LOGO! Soft Comfort software versions prior to V8.2 are susceptible to a vulnerability where the integrity of downloaded software packages is not verified. This flaw allows a remote attacker to exploit an unprotected communication channel to manipulate the software package. Such attacks can occur through a Man-in-the-Middle method, putting the integrity and security of the impacted systems at risk, as malicious actors can intervene during the download process and alter the software without detection.
Affected Version(s)
Siemens LOGO! Soft Comfort (All before V8.2) Siemens LOGO! Soft Comfort (All versions before V8.2)
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved