Siemens LOGO! Crypto Fix Requires Hardware Upgrade
The hardcoded-key and unsalted-hash vulnerabilities in LOGO! Soft Comfort survive a software-only V9 upgrade, closing only when the underlying hardware is also replaced with LOGO! V9 BM.
TL;DR
Siemens LOGO! Soft Comfort versions before V9 ship with a hardcoded AES master key for project-file encryption (CVE-2026-57262) and store project passwords as unsalted SHA-256 hashes (CVE-2026-57263). Both carry a 6.8 CVSS v3.1 base score with a local attack vector. Siemens' fix updates the software to V9, but a compatibility-mode footnote in the advisory means the vulnerabilities persist unless users also upgrade to LOGO! V9 BM hardware. That turns a patch cycle into a procurement and downtime project.
Siemens disclosed two cryptographic vulnerabilities in LOGO! Soft Comfort, the programming tool for its widely deployed LOGO! logic controllers. Both CVEs carry a 6.8 CVSS v3.1 base score with a local attack vector: CVE-2026-57262 is a hardcoded AES master key used to encrypt project files, and CVE-2026-57263 is the storage of project passwords as unsalted SHA-256 hashes. An attacker with local access to the engineering workstation could extract the key from application memory, decrypt project data, strip passwords, or run dictionary attacks against the unsalted hashes.
The remediation is where the advisory gets operationally significant. Siemens recommends updating to LOGO! Soft Comfort V9, but appends a note that a hardware upgrade to LOGO! V9 BM or later is also required. Without new hardware, the software runs in compatibility mode, which preserves both vulnerabilities. For a facilities or transportation-systems operator with dozens of deployed LOGO! units, that isn't a patch-Tuesday fix. It's a capital expenditure with procurement lead times, validation testing, and scheduled downtime.
The advisory, republished by CISA through its ICS advisory channel, covers deployments worldwide across commercial facilities and transportation systems. Siemens ProductCERT reported the vulnerabilities directly rather than receiving them from an external researcher.
Published ·Updated ·Deep Fathom