CVE Feed

    Dashboard / CVE / CVE-2017-6871

    CVE-2017-6871

    A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.

    Published:Aug 8, 2017
    Last Modified:Apr 20, 2025
    EPS:Aug 8, 2017
    EPSS Score:0.00059
    CVSS Score:5.4

    Affected Products

    Vendor
    Siemens
    Product
    Simatic Wincc Sm\@rtclient
    Vendor
    Siemens
    Product
    Simatic Wincc Sm\@rtclient Lite

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High