CVE-2017-6871
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2).
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-288, CWE-287
- Affected
- siemens/simatic wincc sm\@rtclient · siemens/simatic wincc sm\@rtclient lite
- Source
- productcert@siemens.com
References
- http://www.securityfocus.com/bid/99582Third Party Advisory, VDB Entry
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-589378.pdfVendor Advisory
- http://www.securityfocus.com/bid/99582Third Party Advisory, VDB Entry
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-589378.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.