CVE-2014-5232: Low severity siemens simatic wincc sm@rtclient vulnerability
Published Jan 14, 2015
·Updated
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the app in the background state.
Affected Software
2 affected components
Siemens Simatic Wincc Sm\@rtclient<=1.0
Apple iPhone OS
Event History
Jan 14, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5232?
CVE-2014-5232 is considered a medium severity vulnerability due to its potential to allow unauthorized access to the application.
2
How do I fix CVE-2014-5232?
To fix CVE-2014-5232, update the Siemens SIMATIC WinCC Sm@rtClient app to version 1.0.2 or later.
3
Who is affected by CVE-2014-5232?
CVE-2014-5232 affects local users of the Siemens SIMATIC WinCC Sm@rtClient app version 1.0 or lower on iOS devices.
4
What type of vulnerability is CVE-2014-5232?
CVE-2014-5232 is a local authentication bypass vulnerability.
5
Is CVE-2014-5232 specific to any operating system?
Yes, CVE-2014-5232 specifically impacts the iOS version of the Siemens SIMATIC WinCC Sm@rtClient app.