A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). An attacker who performs a Man-in-the-Middle attack between the LOGO! BM and other devices could potentially decrypt and modify network traffic.
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/100561 | third party advisory vdb entry |
https://cert-portal.siemens.com/productcert/pdf/ssa-087240.pdf | vendor advisory |