CVE-2026-57263
Received Received - Intake

Password Hashing Flaw in LOGO! Soft Comfort

Vulnerability report for CVE-2026-57263, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Siemens AG

Description

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siemens logo_soft_comfort to 9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-759 The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects LOGO! Soft Comfort versions before V9. It involves the project password feature storing passwords as unsalted SHA-256 hashes, which are vulnerable to offline dictionary or brute-force attacks if an attacker gains access to the project file.

Detection Guidance

This vulnerability is related to project files stored locally rather than network services. Detection involves checking for LOGO! Soft Comfort installations and examining project files for weak password storage. Inspect project files for unsalted SHA-256 hashes in configuration or metadata.

Impact Analysis

An attacker who obtains the project file could crack the unsalted SHA-256 hash to recover the original password. This may lead to unauthorized access to sensitive project data or control over the system, depending on the password's privileges.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating confidentiality requirements in GDPR or HIPAA. Organizations using affected versions may face compliance risks due to inadequate password protection.

Mitigation Strategies

Upgrade LOGO! Soft Comfort to version V9 or later to address the unsalted hash storage issue. Avoid storing sensitive project files with passwords and implement strong password policies. Monitor for unauthorized access to project files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57263. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart