CVE-2017-6870: High severity siemens simatic wincc sm@rtclient vulnerability
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Middle (MitM) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6870?
CVE-2017-6870 has been classified with a high severity due to its potential for data exposure and manipulation during a Man-in-the-Middle attack.
How do I fix CVE-2017-6870?
To fix CVE-2017-6870, upgrade Siemens SIMATIC WinCC Sm@rtClient for Android to version 1.0.2.2 or later.
What software versions are affected by CVE-2017-6870?
CVE-2017-6870 affects all versions of Siemens SIMATIC WinCC Sm@rtClient for Android prior to version 1.0.2.2.
What kind of attack does CVE-2017-6870 enable?
CVE-2017-6870 enables attackers to perform a Man-in-the-Middle (MitM) attack, allowing them to intercept and alter data within a TLS session.
Is there a risk of data compromise with CVE-2017-6870?
Yes, due to its vulnerability in the TLS implementation, CVE-2017-6870 poses a significant risk of data compromise during communication sessions.