Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99fm-5qxm-cg7x

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.

A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.

EPSS

Процентиль: 10%
0.00034
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 4.6
nvd
почти 8 лет назад

A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.

EPSS

Процентиль: 10%
0.00034
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-311