Executive brief
LOGO! Soft Comfort is engineering software used to program industrial control devices (LOGO! BM modules). The software protects project files using a hardcoded AES encryption key that is the same across all installations. An attacker with local access to a computer running this software can extract the master key and decrypt project files or remove password protection, potentially gaining unauthorized access to sensitive industrial control logic and configurations.
Technical details
The vulnerability is a hardcoded cryptographic key (CWE-321) used to encrypt project files in LOGO! Soft Comfort. An attacker with local system access can extract the static master key from application files or memory, then use it to decrypt any project file or bypass password protections without knowing the user-defined password. The attack requires local access and no user interaction, making it practical for any user on an affected system. The vulnerability affects all versions prior to V9, and Siemens has released a patch requiring both software update to V9 and a hardware upgrade to LOGO! V9 BM or later to fully remediate the issue (earlier hardware versions remain vulnerable even with software patches).
Affected products
- Siemens LOGO! Soft Comfort All versions < V9
Timeline
- 2026-08-11: disclosed