PT-2018-16566 · Siemens · Simatic Wincc Oa Operator Ios App
Published
2018-04-23
·
Updated
2019-10-03
·
CVE-2018-4847
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SIMATIC WinCC OA Operator iOS App versions prior to V1.4
Description
A security issue has been identified due to insufficient protection of sensitive information, such as session keys for accessing the server, in the Siemens WinCC OA Operator iOS app. This could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory.
Recommendations
For versions prior to V1.4, apply the mitigations provided by Siemens to resolve the security issue.
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simatic Wincc Oa Operator Ios App