CVE-2015-1598: Infoleak
Published Mar 7, 2015
·Updated
The Siemens SPCanywhere application for Android does not properly store application passwords, which allows physically proximate attackers to obtain sensitive information by examining the device filesystem.
Affected Software
1 affected component
Siemens SPCanywhere<=1.4.1
Event History
Mar 7, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1598?
CVE-2015-1598 has a medium severity rating due to its potential to expose sensitive information.
2
How do I fix CVE-2015-1598?
To fix CVE-2015-1598, update the Siemens SPCanywhere application to version 1.4.2 or later.
3
Which versions of Siemens SPCanywhere are vulnerable to CVE-2015-1598?
Versions of Siemens SPCanywhere up to and including 1.4.1 are vulnerable to CVE-2015-1598.
4
What type of information can be exposed due to CVE-2015-1598?
CVE-2015-1598 can lead to exposure of sensitive application passwords stored insecurely.
5
Who is affected by CVE-2015-1598?
Users of the Siemens SPCanywhere application for Android prior to version 1.4.2 are affected by CVE-2015-1598.