VORANT. Threat Intelligence Sign in Get the full feed

Siemens LOGO! Soft Comfort has hardcoded crypto key

routine vulnerability manufacturingtransportation

Siemens LOGO! Soft Comfort before V9 uses a hardcoded AES master key and unsalted password hashes, letting local attackers decrypt or crack project files.

Siemens has disclosed two vulnerabilities in LOGO! Soft Comfort, the configuration software for its LOGO! programmable logic controllers used across commercial facilities and transportation infrastructure worldwide. The first issue, CVE-2026-57262, stems from a static, hardcoded AES master key embedded in the application used to encrypt project files. A local attacker who extracts this key from application files or memory can decrypt project files or strip passwords entirely, bypassing the intended protection without ever knowing the legitimate password.

The second issue, CVE-2026-57263, involves the project password feature storing credentials as unsalted SHA-256 hashes. Anyone who obtains a project file can run efficient offline dictionary or brute-force attacks against the hash to recover the plaintext password, since the lack of salting removes the computational cost that salted hashing would normally impose. Both flaws require local access to exploit and primarily threaten confidentiality and integrity of PLC project logic and configuration data rather than enabling remote compromise.

Siemens has released LOGO! Soft Comfort V9 to address both issues, though a corresponding hardware upgrade to LOGO! V9 BM or later is also required — devices running in compatibility mode remain vulnerable even after the software update. CISA republished the Siemens ProductCERT advisory (SSA-751328) and reiterates standard ICS hardening guidance: minimizing network exposure, isolating control system networks behind firewalls, and using VPNs for remote access. No known exploitation in the wild has been reported.

Mentioned in this report

Vulnerabilities CVE-2026-57262CVE-2026-57263

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-13

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free