A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.
History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens logo! Soft Comfort
Vendors & Products Siemens
Siemens logo! Soft Comfort

Wed, 12 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Hardcoded Master Key Enables Local Decryption of LOGO! Soft Comfort Project Files

Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T12:20:21.896Z

Reserved: 2026-06-24T04:43:34.162Z

Link: CVE-2026-57262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T13:18:59.463

Modified: 2026-08-11T13:18:59.463

Link: CVE-2026-57262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:00:03Z