Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f96f-m7rh-gphp

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 6.8

Описание

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.

EPSS

Процентиль: 1%
0.00112
Низкий

7 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 6.8
nvd
27 дней назад

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.

EPSS

Процентиль: 1%
0.00112
Низкий

7 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-321