Security Flaw in QMS Automotive Application from Siemens
CVE-2023-40729

7.4HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 September 2023

Summary

A security control weakness has been discovered in QMS Automotive versions prior to V12.39, allowing unencrypted communication to occur without the protection of HTTPS. This flaw makes the application susceptible to machine-in-the-middle attacks, where an attacker could intercept, manipulate, or steal sensitive data being transmitted. The absence of proper encryption safeguards significantly increases the risk to confidential information handled by the application.

Affected Version(s)

QMS Automotive All versions < V12.39

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.