SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-6871

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2).

MEDIUM 5.4EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.

CVSS 3.0
5.4 MEDIUMCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Weakness
CWE-288, CWE-287
Affected
siemens/simatic wincc sm\@rtclient · siemens/simatic wincc sm\@rtclient lite
Source
productcert@siemens.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.