CVE-2018-4847
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.
Se ha identificado una vulnerabilidad en SIMATIC WinCC OA Operator iOS App (todas las versiones anteriores a la V1.4). La protección insuficiente de información sensible (por ejemplo, la clave de sesión para acceder al servidor) en la aplicación para iOS de Siemens WinCC OA Operator podría permitir que un atacante con acceso físico al dispositivo móvil lea datos no cifrados del directorio de la aplicación. Siemens proporciona mitigaciones para resolver este problema de seguridad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-02 CVE Reserved
- 2018-04-23 CVE Published
- 2023-09-14 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-311: Missing Encryption of Sensitive Data
- CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103941 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-597741.pdf | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Wincc Oa Operator Search vendor "Siemens" for product "Simatic Wincc Oa Operator" | - | iphone_os |
Affected
|