You are here

Siemens SIMATIC WinCC OA Operator IOS App (Update A) (ICSA-18-109-01) – Products Used in the Water and Wastewater and Energy Sectors

Siemens SIMATIC WinCC OA Operator IOS App (Update A) (ICSA-18-109-01) – Products Used in the Water and Wastewater and Energy Sectors

Created: Thursday, October 11, 2018 - 12:29
Categories:
Cybersecurity

October 9, 2018

The NCCIC has updated this advisory with additional details on the affected products and mitigation measures. NCCIC/ICS-CERT.

April 9, 2018

The NCCIC has released an advisory on a file and information directory exposure vulnerability in Siemens SIMATIC WinCC OA Operator IOS App. All versions prior to 1.4 are affected. Successful exploitation of this vulnerability could allow an attacker with physical access to read sensitive data located in the app’s directory. Siemens has recommended that users update to v1.4. The NCCIC also recommends a series of defensive measures to minimize the risk of exploitation of these vulnerabilities. NCCIC/ICS-CERT.