PT-2018-16566 · Siemens · Simatic Wincc Oa Operator Ios App
Publicado
2018-04-23
·
Atualizado
2019-10-03
·
CVE-2018-4847
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SIMATIC WinCC OA Operator iOS App versions prior to V1.4
Description
A security issue has been identified due to insufficient protection of sensitive information, such as session keys for accessing the server, in the Siemens WinCC OA Operator iOS app. This could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory.
Recommendations
For versions prior to V1.4, apply the mitigations provided by Siemens to resolve the security issue.
Correção
Missing Encryption of Sensitive Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Simatic Wincc Oa Operator Ios App