PT-2017-17386 · Siemens · Simatic Wincc Sm@Rtclient For Android
Published
2017-08-08
·
Updated
2019-10-09
·
CVE-2017-6871
CVSS v3.1
5.4
Medium
| Vector | AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC WinCC Sm@rtClient for Android versions prior to 1.0.2.2
Siemens SIMATIC WinCC Sm@rtClient for Android Lite versions prior to 1.0.2.2
Description
A vulnerability was discovered that allows an attacker with physical access to an unlocked mobile device to bypass the app's authentication mechanism under certain conditions.
Recommendations
For Siemens SIMATIC WinCC Sm@rtClient for Android versions prior to 1.0.2.2, update to version 1.0.2.2 or later to resolve the issue.
For Siemens SIMATIC WinCC Sm@rtClient for Android Lite versions prior to 1.0.2.2, update to version 1.0.2.2 or later to resolve the issue.
Fix
Authentication Bypass Using an Alternate Path or Channel
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simatic Wincc Sm@Rtclient For Android