Impact
The vulnerability lies in the storage of the project password as an unsalted SHA‑256 hash in the LOGO! Soft Comfort project file. Because the hash is unsalted, an attacker who obtains the project file can perform efficient offline dictionary or brute‑force attacks to recover the password. This leads to unauthorized access to the project and potential tampering or data exposure. The weakness is a hashed credential storage failure, consistent with CWE‑759.
Affected Systems
Siemens LOGO! Soft Comfort products, all versions earlier than V9.
Risk and Exploitability
The CVSS score of 7 indicates moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires the attacker to have access to the project file; it can then be used to launch offline cryptanalysis attacks. The exploitation likelihood depends on how readily the project file is exposed, but once obtained, the password can be cracked efficiently due to the lack of salting.
OpenCVE Enrichment