Inconsistent Error Message Vulnerability in QMS Automotive by Siemens
CVE-2023-40725

4MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 September 2023

Summary

A vulnerability has been discovered in QMS Automotive where the application generates inconsistent error messages during login attempts with invalid user credentials. This issue could be exploited by an attacker to enumerate valid usernames, posing a significant risk as it could potentially lead to unauthorized access and further attacks on the system. It is crucial for organizations using this software to update to version 12.39 or later to mitigate this risk.

Affected Version(s)

QMS Automotive All versions < V12.39

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.