Siemens LOGO! Soft Comfort

MonitorCVSS 6.8ICS-CERT ICSA-26-225-13Aug 11, 2026
Siemens
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

LOGO! Soft Comfort versions prior to V9 contain a hardcoded AES master key that can be extracted by a local attacker. Additionally, project password hashes lack salt protection, enabling offline dictionary or brute-force attacks. An attacker with local access to an engineering workstation can extract the master key to decrypt project files, remove password protection, or view and modify sensitive automation logic. The vulnerability is present in both the software and controllers running in compatibility mode with older hardware versions.

What this means
What could happen
An attacker with local access to a workstation running LOGO! Soft Comfort could extract the hardcoded encryption master key, decrypt project files, or remove password protection from logic programs. This allows unauthorized viewing or modification of industrial process logic and setpoints.
Who's at risk
This affects facilities that use Siemens LOGO! controllers for process automation, including small manufacturing plants, water treatment systems, building automation, and any operation that relies on LOGO! Soft Comfort for programming or managing logic controllers. Engineering staff and anyone with workstation access poses a risk if systems are not updated.
How it could be exploited
An attacker gains local access to an engineering workstation running LOGO! Soft Comfort, extracts the recoverable hardcoded AES master key from the application, and uses it to decrypt project files or brute-force password hashes (which lack salt protection). No network access is required.
Prerequisites
  • Local access to the engineering workstation running LOGO! Soft Comfort < V9
  • No credentials required to extract the master key from the application
  • Project file (.lgo or similar) must be accessible on the workstation
Local access required but no authentication neededLow complexity exploitationHardcoded encryption key recoverable from applicationAffects sensitive project logic and configurations
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (1)
ProductAffected VersionsFix Status
LOGO! Soft Comfort < V9< 9Fix available
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict physical and remote access to engineering workstations to authorized personnel only
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate LOGO! Soft Comfort to version 9 or later
HOTFIXUpgrade LOGO! hardware controllers to V9 BM or later to avoid running in compatibility mode, which retains the vulnerabilities
Long-term hardening
0/1
HARDENINGImplement full-disk encryption on all workstations running LOGO! Soft Comfort to protect project files at rest
API: /api/v1/advisories/b0eb042b-21fe-4f2d-878f-507932cac6ac

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Siemens LOGO! Soft Comfort | CVSS 6.8 - OTPulse