Lucene search

K
cveSiemensCVE-2018-4847
HistoryApr 23, 2018 - 4:29 p.m.

CVE-2018-4847

2018-04-2316:29:00
CWE-311
CWE-538
siemens
web.nvd.nist.gov
27
cve-2018-4847
vulnerability
simatic wincc
ios app
siemens
nvd
security issue

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4

Confidence

High

EPSS

0.001

Percentile

21.9%

A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app’s directory. Siemens provides mitigations to resolve the security issue.

Affected configurations

Nvd
Node
siemenssimatic_wincc_oa_operatorMatch-iphone_os
VendorProductVersionCPE
siemenssimatic_wincc_oa_operator-cpe:2.3:a:siemens:simatic_wincc_oa_operator:-:*:*:*:*:iphone_os:*:*

CNA Affected

[
  {
    "product": "SIMATIC WinCC OA Operator iOS App",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V1.4"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4

Confidence

High

EPSS

0.001

Percentile

21.9%

Related for CVE-2018-4847