ICSA-18-109-01
·
Published 2018-10-09
·
View on CISA ICS-CERT ↗
Siemens SIMATIC WinCC OA Operator IOS App (Update A)
CVSS 4.0
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an attacker with physical access to read sensitive data located in the app 's directory.
CVEs (1)
Remediations
- Siemens has recommended that users update to v1.4, which can be located here:
- Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk: Toggle off the button to save password while logging in and logout after every work session.
- Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk: Follow the SIMATIC WinCC OA Security Guideline (available at https://portal.etm.at/index.php? option=com_phocadownload&view=category&id=52:security&Itemid=81) for maintaining a secured SIMATIC WinCC OA environment.
- Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk: Siemens does not recommend to use the app in high security areas.
- As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and following the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity
- For more information on this vulnerability and associated mitigation practices please see Siemens security advisory SSA-597741 on their website:
Affected Vendors
Siemens
Affected Products (1)
Siemens
·
SIMATIC WinCC OA Operator iOS App
< 1.4
Affected Sectors
Chemical, Energy, Food and Agriculture, and Water and Wastewater Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more