A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2018-04-23T16:00:00Z
Updated: 2024-09-17T02:57:39.805Z
Reserved: 2018-01-02T00:00:00
Link: CVE-2018-4847
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-04-23T16:29:00.213
Modified: 2024-11-21T04:07:34.623
Link: CVE-2018-4847
Redhat
No data.