A total of three vulnerabilities have been removed by Siemensin the iOS version of SIMATIC WinCC Sm@rtClient, reducing the risk for an attacker to intercept account access credentials, but under certain conditions.
The SIMATIC WinCC Sm@rtClient, together with its Sm@rtServer functionality, has been designed as an easy way to control from a mobile device, the SIMATIC HMI, so that it can be used for managing industrial control systems (ICS).
The current updated version released by Siemens is available from the Apple store and fixes security vulnerabilities that affect all client versions, before 1.0.2, including the Lite versions.
All vulnerabilities have received a base score of 4.6 CVSS and the overall score is 3.6. One of them, identified as CVE-2014-5231, refers to the way the application password was stored. There was also the risk of the password being stolen along with other sensitive information if a hacker gained access to the local network.
Another issue, identified as CVE-2014-5232, is the fact that the user would not be prompted to re-enter the password if the app was restored from the background.
In the third case, (CVE-2014-5233), an individual could be able to extract credentials from the Sm@rtServer portion of the app.
It is worth noting that access to the local network is necessary in order to exploit any of the above vulnerabilities. Users are encouraged to install the latest versions of the app to reduce the risks mentioned and be more secure.

