CVE-2014-5233: Infoleak
Published Jan 14, 2015
·Updated
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.
Affected Software
2 affected components
Siemens Simatic Wincc Sm\@rtclient<=1.0
Apple iPhone OS
Event History
Jan 14, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5233?
CVE-2014-5233 has a medium severity rating due to its potential for credential discovery.
2
How do I fix CVE-2014-5233?
To fix CVE-2014-5233, update the Siemens SIMATIC WinCC Sm@rtClient app to version 1.0.2 or later.
3
Who is affected by CVE-2014-5233?
Users of the Siemens SIMATIC WinCC Sm@rtClient app version prior to 1.0.2 for iOS are affected by CVE-2014-5233.
4
What type of attack is related to CVE-2014-5233?
CVE-2014-5233 is related to physical proximity attacks that exploit an error in credential processing.
5
What are the consequences of CVE-2014-5233?
The consequences of CVE-2014-5233 include unauthorized disclosure of Sm@rtServer credentials.