CVE-2022-36360: Siemens logo!8 Bm Fs-05 Firmware

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verified by a non-cryptographic method. This could allow an attacker to manipulate a firmware update and flash it to the device.

Affected products

  • Siemens logo!8 Bm Fs-05 Firmware: before 8.3 (fixed in 8.3)
  • Siemens Logo! 8 Bm Firmware: before 8.3 (fixed in 8.3)

Published 2022-10-11. Last modified 2026-06-17.