Vulnerabilities > CVE-2017-6870 - Unspecified vulnerability in Siemens Simatic Wincc Sm@Rtclient 1.0/1.0.2.1

047910
CVSS 7.4 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
high complexity
siemens

Summary

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Middle (MitM) attack.

Vulnerable Configurations

Part Description Count
Application
Siemens
2