CVE-2017-6870: Siemens SIMATIC Wincc Sm@rtclient

High severity, CVSS 7.4. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Middle (MitM) attack.

Affected products

  • Siemens SIMATIC Wincc Sm@rtclient: up to and including 1.0.2.1

Published 2017-08-08. Last modified 2026-06-17.