Encryption Vulnerability in LOGO! Soft Comfort by Siemens
CVE-2026-57262

7HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
11 August 2026

What is CVE-2026-57262?

A significant vulnerability exists in LOGO! Soft Comfort that involves the use of a static, hardcoded AES master key for project file encryption. This flaw enables a local attacker to potentially extract the master key from either the application files or memory. Once the master key is compromised, it can be employed to decrypt project files or entirely remove project passwords, effectively bypassing user-defined security measures and compromising the integrity of sensitive project data.

Affected Version(s)

LOGO! Soft Comfort 0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.