CVE-2014-5233 describes a vulnerability in the Siemens SIMATIC WinCC Sm@rtClient app for iOS, specifically versions prior to 1.0.2, where an error in credential processing allows physically proximate attackers to discover Sm@rtServer credentials. This is a low-severity issue with a CVSS score of 1.9, requiring physical access to the device (AV:L) and moderate attack complexity (AC:M) to achieve partial confidentiality (C:P) of credentials. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention and media article from SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0CPE matchmatch criteria | cpe:2.3:a:siemens:simatic_wincc_sm\@rtclient:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.