CVE-2017-6871: Medium severity siemens simatic wincc sm@rtclient vulnerability
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6871?
CVE-2017-6871 is characterized as a moderate vulnerability due to the requirement of physical access to the device.
How do I fix CVE-2017-6871?
To fix CVE-2017-6871, update the Siemens SIMATIC WinCC Sm@rtClient and SIMATIC WinCC Sm@rtClient Lite apps to version 1.0.2.2 or later.
What are the affected versions of the software related to CVE-2017-6871?
All versions of Siemens SIMATIC WinCC Sm@rtClient and SIMATIC WinCC Sm@rtClient Lite prior to version 1.0.2.2 are affected by CVE-2017-6871.
Can CVE-2017-6871 be exploited remotely?
CVE-2017-6871 cannot be exploited remotely as the attacker must have physical access to an unlocked mobile device.
Who is affected by CVE-2017-6871?
Users of Siemens SIMATIC WinCC Sm@rtClient and SIMATIC WinCC Sm@rtClient Lite applications on Android devices prior to version 1.0.2.2 are affected by CVE-2017-6871.