Inconsistent Error Message Vulnerability in QMS Automotive by Siemens
CVE-2023-40725
4MEDIUM
Summary
A vulnerability has been discovered in QMS Automotive where the application generates inconsistent error messages during login attempts with invalid user credentials. This issue could be exploited by an attacker to enumerate valid usernames, posing a significant risk as it could potentially lead to unauthorized access and further attacks on the system. It is crucial for organizations using this software to update to version 12.39 or later to mitigate this risk.
Affected Version(s)
QMS Automotive All versions < V12.39
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved