CVE-2022-36360: Siemens logo!8 Bm Fs-05 Firmware
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verified by a non-cryptographic method. This could allow an attacker to manipulate a firmware update and flash it to the device.
Affected products
- Siemens logo!8 Bm Fs-05 Firmware: before 8.3 (fixed in 8.3)
- Siemens Logo! 8 Bm Firmware: before 8.3 (fixed in 8.3)
Published 2022-10-11. Last modified 2026-06-17.