High severity7.5NVD Advisory· Published May 14, 2019· Updated Jun 17, 2026
CVE-2019-10920
CVE-2019-10920
Description
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Project data stored on the device, which is accessible via port 10005/tcp, can be decrypted due to a hardcoded encryption key. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 10005/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:siemens:logo\!8_bm_firmware:*:*:*:*:*:*:*:*
- Range: <V8.3
- Siemens/LOGO! 8 BM (incl. SIPLUS variants)v5Range: All versions < V8.3
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/153122/Siemens-LOGO-8-Hard-Coded-Cryptographic-Key.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/May/44nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/108382nvdThird Party AdvisoryVDB Entry
- cert-portal.siemens.com/productcert/pdf/ssa-542701.pdfnvdVendor Advisory
- seclists.org/bugtraq/2019/May/72nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.