← Back to home
ICSA-18-109-01  ·  Published 2018-10-09  ·  View on CISA ICS-CERT ↗

Siemens SIMATIC WinCC OA Operator IOS App (Update A)

CVSS 4.0 MEDIUM

Risk Summary

Successful exploitation of this vulnerability could allow an attacker with physical access to read sensitive data located in the app 's directory.

CVEs (1)

Remediations

  • Siemens has recommended that users update to v1.4, which can be located here:
  • Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk: Toggle off the button to save password while logging in and logout after every work session.
  • Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk: Follow the SIMATIC WinCC OA Security Guideline (available at https://portal.etm.at/index.php? option=com_phocadownload&view=category&id=52:security&Itemid=81) for maintaining a secured SIMATIC WinCC OA environment.
  • Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk: Siemens does not recommend to use the app in high security areas.
  • As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and following the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity
  • For more information on this vulnerability and associated mitigation practices please see Siemens security advisory SSA-597741 on their website:

Affected Vendors

Siemens

Affected Products (1)

Siemens · SIMATIC WinCC OA Operator iOS App < 1.4

Affected Sectors

Chemical, Energy, Food and Agriculture, and Water and Wastewater Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more