Security Flaw in QMS Automotive Application from Siemens
CVE-2023-40729
7.4HIGH
Summary
A security control weakness has been discovered in QMS Automotive versions prior to V12.39, allowing unencrypted communication to occur without the protection of HTTPS. This flaw makes the application susceptible to machine-in-the-middle attacks, where an attacker could intercept, manipulate, or steal sensitive data being transmitted. The absence of proper encryption safeguards significantly increases the risk to confidential information handled by the application.
Affected Version(s)
QMS Automotive All versions < V12.39
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved