The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-267489.pdf | patch vendor advisory |
http://www.securityfocus.com/bid/75981 | vdb entry |
http://www.securitytracker.com/id/1033021 | vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-15-202-02 | third party advisory us government resource |