A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The firmware update of affected devices contains the private RSA key that is used as a basis for encryption of communication with the device.
The product uses a hard-coded, unchangeable cryptographic key.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-480824.pdf | vendor advisory |