Impact
The vulnerability stems from a static, hardcoded AES master key used to encrypt project files in Siemens LOGO! Soft Comfort. An attacker who can access the application files or memory on the device can extract this master key, which then allows decryption of any project file or outright removal of the user‑defined password protecting those files. This directly compromises the confidentiality and integrity of user data stored on the device.
Affected Systems
Affected systems are all versions of Siemens LOGO! Soft Comfort prior to V9. The product, typically used on industrial automation controllers, includes the insecure key material in its binary and configuration files, rendering earlier releases vulnerable to the described local key recovery and decryption scenario.
Risk and Exploitability
The CVSS score of 7 signifies a medium‑to‑high severity, and although the EPSS score is not reported, the attack requires local access, limiting its likelihood to environments where an attacker can physically interact with the device or has already compromised it. The vulnerability is not listed in the CISA KEV catalog, but its exploitation potential is real for deployments that have not been updated. Because the weak key storage is a reversible flaw, no additional software conditions are required beyond local file or memory access.
OpenCVE Enrichment