CVE-2018-4844 - CVE House
Back to Database
Status published Medium CVE-2018-4844

A vulnerability has been identified in SIMATIC WinCC OA UI...

Vulnerability Description

A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.10). Insufficient limitation of CONTROL script capabilities could allow read and write access from one HMI project cache folder to other HMI project cache folders within the app's sandbox on the same mobile device. This includes HMI project cache folders of other configured WinCC OA servers. The security vulnerability could be exploited by an attacker who tricks an app user to connect to an attacker-controlled WinCC OA server. Successful exploitation requires user interaction and read/write access to the app's folder on a mobile device. The vulnerability could allow reading data from and writing data to the app's folder. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-4844

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SIMATIC WinCC OA UI for Android, SIMATIC WinCC OA UI for iOS
Vulnerable Versions:
SIMATIC WinCC OA UI for Android : All versions < V3.15.10, SIMATIC WinCC OA UI for iOS : All versions < V3.15.10

Timeline

Official Publish: March 20th, 2018
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Weaknesses (CWE)