CVE-2017-12740
5.9MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 26 December 2017
Summary
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.
Affected Version(s)
Siemens LOGO! Soft Comfort (All before V8.2) Siemens LOGO! Soft Comfort (All versions before V8.2)
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved