CVE-2018-4847
Last modified
CVE-2018-4847 is a vulnerability of currently unknown severity. A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Simatic Wincc Oa Operator | All versions |
References
- http://www.securityfocus.com/bid/103941Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103941Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-4847?
How severe is CVE-2018-4847?
How do I fix CVE-2018-4847?
Are you affected by CVE-2018-4847?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
