CVE-2015-1597: Code Injection
The Siemens SPCanywhere application for Android does not use encryption during the loading of code, which allows man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1597?
CVE-2015-1597 is classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2015-1597?
To mitigate CVE-2015-1597, update the Siemens SPCanywhere application to a version newer than 1.4.1, if available.
What type of attack does CVE-2015-1597 expose users to?
CVE-2015-1597 exposes users to man-in-the-middle attacks, allowing attackers to manipulate the client-server data stream.
Which versions of Siemens SPCanywhere are affected by CVE-2015-1597?
CVE-2015-1597 affects Siemens SPCanywhere versions up to and including 1.4.1 on Android.
Is encryption used in the Siemens SPCanywhere application as per CVE-2015-1597?
No, the Siemens SPCanywhere application does not use encryption during the loading of code, which contributes to the vulnerability.