Encryption Vulnerability in LOGO! Soft Comfort by Siemens
CVE-2026-57262
7HIGH
What is CVE-2026-57262?
A significant vulnerability exists in LOGO! Soft Comfort that involves the use of a static, hardcoded AES master key for project file encryption. This flaw enables a local attacker to potentially extract the master key from either the application files or memory. Once the master key is compromised, it can be employed to decrypt project files or entirely remove project passwords, effectively bypassing user-defined security measures and compromising the integrity of sensitive project data.
Affected Version(s)
LOGO! Soft Comfort 0