CyberRota Analysis
AI-GeneratedThe project password feature in LOGO! Soft Comfort versions prior to V9 is vulnerable due to the storage of passwords as unsalted SHA-256 hashes, enabling attackers to execute efficient offline dictionary or brute-force attacks if they gain access to the project file. Organizations using this software should prioritize remediation to protect sensitive project data from potential unauthorized access. This vulnerability is particularly relevant for users managing critical automation projects where password security is paramount.
Original NVD Description
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.