Vigil@nce - SIMATIC WinCC Sm@rtClient for Android: two vulnerabilities
October 2017 by Vigil@nce
This bulletin was written by Vigil@nce : https://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can use several vulnerabilities of SIMATIC WinCC
Sm@rtClient for Android.
Impacted products: Android Applications not comprehensive,
SIMATIC.
Severity: 2/4.
Creation date: 08/08/2017.
DESCRIPTION OF THE VULNERABILITY
Several vulnerabilities were announced in SIMATIC WinCC
Sm@rtClient for Android.
An attacker can act as a Man-in-the-Middle, in order to read or
write data in the session. [severity:2/4; CVE-2017-6870]
An attacker can bypass security features via Unlocked Mobile
Device, in order to escalate his privileges. [severity:1/4;
CVE-2017-6871]
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN
https://vigilance.fr/vulnerability/SIMATIC-WinCC-Sm-rtClient-for-Android-two-vulnerabilities-23468