VulnerabilityModified
CVE-2017-12740
This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.
MEDIUM 5.9EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-494, CWE-345
- Affected
- siemens/logo\! soft comfort
- Source
- productcert@siemens.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.