First published: Tue Sep 12 2023(Updated: )
A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Qms Automotive | <12.39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-40724.
The severity of CVE-2023-40724 is high with a severity value of 7.3.
The affected software for CVE-2023-40724 is QMS Automotive with all versions prior to V12.39.
CVE-2023-40724 allows an attacker to access user credentials that are stored in memory as plaintext, potentially leading to unauthorized access and impersonation.
To mitigate CVE-2023-40724, it is recommended to update QMS Automotive to version V12.39 or newer, which addresses the vulnerability.