PT-2018-16566 · Siemens · Simatic Wincc Oa Operator Ios App

Published

2018-04-23

·

Updated

2019-10-03

·

CVE-2018-4847

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SIMATIC WinCC OA Operator iOS App versions prior to V1.4
Description A security issue has been identified due to insufficient protection of sensitive information, such as session keys for accessing the server, in the Siemens WinCC OA Operator iOS app. This could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory.
Recommendations For versions prior to V1.4, apply the mitigations provided by Siemens to resolve the security issue.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-4847

Affected Products

Simatic Wincc Oa Operator Ios App