First published: Tue Dec 26 2017(Updated: )
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens LOGO! Soft Comfort | <8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12740 is classified as a medium severity vulnerability.
To fix CVE-2017-12740, update Siemens LOGO! Soft Comfort to version 8.2 or later.
CVE-2017-12740 can be exploited through a Man-in-the-Middle (MitM) attack.
All versions of Siemens LOGO! Soft Comfort prior to version 8.2 are affected by CVE-2017-12740.
The main weakness in CVE-2017-12740 is the lack of integrity verification for software packages downloaded over an unprotected communication channel.