Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-4847

Опубликовано: 23 апр. 2018
Источник: nvd
CVSS3: 4.6
CVSS2: 2.1
EPSS Низкий

Описание

A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:siemens:simatic_wincc_oa_operator:-:*:*:*:*:iphone_os:*:*

EPSS

Процентиль: 10%
0.00034
Низкий

4.6 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-538
CWE-311

Связанные уязвимости

CVSS3: 4.6
github
больше 3 лет назад

A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.

EPSS

Процентиль: 10%
0.00034
Низкий

4.6 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-538
CWE-311