Siemens LOGO! Series Buffer Overflow Vulnerability Allowing Remote Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in multiple LOGO! 8 BM devices, including SIPLUS variants. The issue arises because the affected devices do not properly validate the structure of TCP packets in several methods. This lack of validation could allow an attacker to cause buffer overflows, gain control over the instruction counter, and execute custom code.

Impact

Exploitation of this vulnerability could lead to a buffer overflow, allowing for arbitrary code execution on the affected device.

Remediation

Users are advised to protect the LSC access to the device with a strong password. For specific product remediations or mitigations, refer to the Siemens Security Advisory SSA-267056.

Added: Nov 11, 2025, 9:36 PM
Updated: Nov 11, 2025, 9:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.