Siemens LOGO! Series Devices Missing Validation Vulnerability Allowing IP Address Manipulation

Vulnerability

A vulnerability exists in multiple Siemens LOGO! series devices, including LOGO! 12/24RCE, LOGO! 230RCE, LOGO! 24CE, and their SIPLUS variants, all running any version. The issue arises because these devices fail to perform necessary validations during interactions, potentially allowing an unauthenticated remote attacker to manipulate the device's IP address, rendering the device unreachable.

Impact

Exploitation of this vulnerability could lead to a denial-of-service condition, where the device becomes unreachable due to IP address manipulation.

Remediation

Siemens recommends restricting network access to port 10006/udp to trusted IP addresses. For product-specific remediations or mitigations, refer to the Siemens Security Advisory SSA-267056.

Added: Nov 11, 2025, 9:35 PM
Updated: Nov 11, 2025, 9:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.9
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.