CVE-2022-43958: Critical severity Siemens Qms Automotive vulnerability
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and impersonate other users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QMS Automotiveto a version that resolves this vulnerability.Fixed in V12.39 - Operational
Because user credentials are stored in plaintext in the database without any hashing mechanism, migrate/replace existing stored credentials with a securely hashed representation after upgrading to V12.39.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43958?
The severity of CVE-2022-43958 is critical.
What is the vulnerability description of CVE-2022-43958?
CVE-2022-43958 is a vulnerability in QMS Automotive (All versions < V12.39) where user credentials are stored in plaintext in the database without any hashing mechanism.
How can an attacker exploit CVE-2022-43958?
An attacker can exploit CVE-2022-43958 by gaining access to the plaintext user credentials stored in the database and impersonating other users.
How can I mitigate CVE-2022-43958?
To mitigate CVE-2022-43958, update QMS Automotive to version V12.39 or later, which addresses the vulnerability by implementing a hashing mechanism for user credentials.
Where can I find more information about CVE-2022-43958?
More information about CVE-2022-43958 can be found in the following references: [SSA-147266.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-147266.pdf) and [SSA-587547.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-587547.pdf).