{"api_version":"1","generated_at":"2026-07-23T05:18:29+00:00","cve":"CVE-2017-6871","urls":{"html":"https://cve.report/CVE-2017-6871","api":"https://cve.report/api/cve/CVE-2017-6871.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-6871","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-6871"},"summary":{"title":"CVE-2017-6871","description":"A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.","state":"PUBLISHED","assigner":"siemens","published_at":"2017-08-08 00:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-288","CWE-287","CWE-288 CWE-288: Authentication Bypass Using an Alternate Path or Channel"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/99582","name":"http://www.securityfocus.com/bid/99582","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Siemens SIMATIC WinCC Sm@rtClient for Android ICSA-17-194-03 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-589378.pdf","name":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-589378.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Siemens","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-6871","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-6871","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"SIMATIC WinCC Sm@rtClient for Android, SIMATIC WinCC Sm@rtClient Lite for Android","version":"affected SIMATIC WinCC Sm@rtClient for Android, SIMATIC WinCC Sm@rtClient Lite for Android","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"6871","vulnerable":"1","versionEndIncluding":"1.0.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"siemens","cpe5":"simatic_wincc_sm\\@rtclient","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"6871","vulnerable":"1","versionEndIncluding":"1.0.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"siemens","cpe5":"simatic_wincc_sm\\@rtclient_lite","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T15:41:17.693Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"99582","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/99582"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-589378.pdf"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"SIMATIC WinCC Sm@rtClient for Android, SIMATIC WinCC Sm@rtClient Lite for Android","vendor":"n/a","versions":[{"status":"affected","version":"SIMATIC WinCC Sm@rtClient for Android, SIMATIC WinCC Sm@rtClient Lite for Android"}]}],"datePublic":"2017-08-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-288","description":"CWE-288: Authentication Bypass Using an Alternate Path or Channel","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-08-08T09:57:01.000Z","orgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","shortName":"siemens"},"references":[{"name":"99582","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/99582"},{"tags":["x_refsource_CONFIRM"],"url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-589378.pdf"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"productcert@siemens.com","ID":"CVE-2017-6871","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"SIMATIC WinCC Sm@rtClient for Android, SIMATIC WinCC Sm@rtClient Lite for Android","version":{"version_data":[{"version_value":"SIMATIC WinCC Sm@rtClient for Android, SIMATIC WinCC Sm@rtClient Lite for Android"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-288: Authentication Bypass Using an Alternate Path or Channel"}]}]},"references":{"reference_data":[{"name":"99582","refsource":"BID","url":"http://www.securityfocus.com/bid/99582"},{"name":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-589378.pdf","refsource":"CONFIRM","url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-589378.pdf"}]}}}},"cveMetadata":{"assignerOrgId":"cec7a2ec-15b4-4faf-bd53-b40f371f3a77","assignerShortName":"siemens","cveId":"CVE-2017-6871","datePublished":"2017-08-08T00:00:00.000Z","dateReserved":"2017-03-13T00:00:00.000Z","dateUpdated":"2024-08-05T15:41:17.693Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-08-08 00:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-288","CWE-287","CWE-288 CWE-288: Authentication Bypass Using an Alternate Path or Channel"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":0.7,"impactScore":4.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:siemens:simatic_wincc_sm\\@rtclient:*:*:*:*:*:android:*:*","versionEndIncluding":"1.0.2.1","matchCriteriaId":"2B041048-D9F4-4F84-9454-8744BF2708EF"},{"vulnerable":true,"criteria":"cpe:2.3:a:siemens:simatic_wincc_sm\\@rtclient_lite:*:*:*:*:*:android:*:*","versionEndIncluding":"1.0.2.1","matchCriteriaId":"F92BEB88-D33F-40EB-8D22-9E86160336E0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"6871","Ordinal":"1","Title":"CVE-2017-6871","CVE":"CVE-2017-6871","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"6871","Ordinal":"1","NoteData":"A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.","Type":"Description","Title":"CVE-2017-6871"},{"CveYear":"2017","CveId":"6871","Ordinal":"2","NoteData":"2017-08-07","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"6871","Ordinal":"3","NoteData":"2017-08-08","Type":"Other","Title":"Modified"}]}}}