Junglewise Threat Intelligence

CVE-2026-57263: Siemens LOGO! Soft Comfort unsalted password hash vulnerability

CVE-2026-57263 · Severity: medium · CVSS 6.8 · Published 2026-08-11

Vendors: Siemens.

Executive brief

LOGO! Soft Comfort is an engineering tool used to configure and program industrial automation devices. The software stores project passwords using an unsalted SHA-256 hash, which makes it vulnerable to efficient offline brute-force or dictionary attacks if an attacker obtains the project file. A successful attack could allow unauthorized access to or modification of critical industrial automation logic and configurations.

Technical details

The vulnerability is a lack of password salting (CWE-759) in the project password feature of LOGO! Soft Comfort. Project passwords are stored as unsalted SHA-256 hashes, allowing an attacker who has obtained a project file to perform efficient offline dictionary or brute-force attacks without the need for authentication or network access. The attack vector is local and requires only the ability to access project files. This could result in unauthorized access to project logic and configurations. The fix is available in LOGO! Soft Comfort V9 and later, with a hardware upgrade to LOGO! V9 BM or later recommended to avoid compatibility mode.

Affected products

  • Siemens LOGO! Soft Comfort All versions < V9

Timeline

  • 2026-08-11: disclosed

References

Related threats