Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-4844

23
FAUCET Score

CVE-2018-4844 is a medium-severity vulnerability affecting Siemens SIMATIC WinCC OA UI for Android and iOS versions prior to V3.15.10. It allows an attacker to gain read and write access to other HMI project cache folders within the app's sandbox on the same mobile device, including those from other WinCC OA servers. This requires user interaction to connect to an attacker-controlled server and read/write access to the app's folder. The CVSS score is 6.7 (Medium), indicating a network attack vector with low attack complexity, requiring user interaction, and resulting in high confidentiality and integrity impacts. There is no known public exploitation, exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.15.10CPE matchmatch criteria
cpe:2.3:a:siemens:simatic_wincc_oa_ui:*:*:*:*:*:android:*:*
< 3.15.10CPE matchmatch criteria
cpe:2.3:a:siemens:simatic_wincc_oa_ui:*:*:*:*:*:iphone_os:*:*

CVSS Data

CVSS version used by this source: 3.1

6.7MEDIUM

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.5
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
34.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 73rd percentile among its peer group of 60 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

ics-cert.us-cert.gov / advisories/ICSA-18-081-01
Third Party AdvisoryUS Government ResourceVDB Entry
cert-portal.siemens.com / productcert/pdf/ssa-822928.pdf
Vendor Advisory
securityfocus.com / bid/103475
Broken LinkThird Party AdvisoryVDB Entry