Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.
References
Link | Resource |
---|---|
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-888929.pdf | Vendor Advisory |
Configurations
Information
Published : 2017-12-25 20:29
Updated : 2019-10-09 16:23
NVD link : CVE-2017-12740
Mitre link : CVE-2017-12740
JSON object : View
CWE
CWE-345
Insufficient Verification of Data Authenticity
Products Affected
siemens
- logo\!_soft_comfort