Description
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-16633 | A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue. |
References
History
No history.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-09-17T02:57:39.805Z
Reserved: 2018-01-02T00:00:00.000Z
Link: CVE-2018-4847
No data.
Status : Modified
Published: 2018-04-23T16:29:00.213
Modified: 2024-11-21T04:07:34.623
Link: CVE-2018-4847
No data.
OpenCVE Enrichment
No data.
EUVD