CVE-2014-5231: Infoleak
Published Jan 14, 2015
·Updated
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors.
Affected Software
2 affected components
Siemens Simatic Wincc Sm\@rtclient<=1.0
Apple iPhone OS
Event History
Jan 14, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5231?
CVE-2014-5231 has been assigned a medium severity rating due to its potential for exposing sensitive user credentials.
2
How do I fix CVE-2014-5231?
To mitigate CVE-2014-5231, update the Siemens SIMATIC WinCC Sm@rtClient app to version 1.0.2 or later.
3
Who is affected by CVE-2014-5231?
Users of Siemens SIMATIC WinCC Sm@rtClient app versions prior to 1.0.2 on iOS are affected by CVE-2014-5231.
4
What type of attack does CVE-2014-5231 involve?
CVE-2014-5231 involves a local attack where physically proximate attackers can extract stored passwords.
5
What are the technical impacts of CVE-2014-5231?
The technical impact of CVE-2014-5231 allows unauthorized users to gain access to stored passwords, potentially compromising user accounts.