CVE-2023-40729: High severity siemens qms automotive vulnerability
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal confidential information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40729?
The severity of CVE-2023-40729 is high with a CVSS score of 7.3.
What is the affected software of CVE-2023-40729?
The affected software of CVE-2023-40729 is QMS Automotive with all versions less than V12.39.
What is the vulnerability description of CVE-2023-40729?
CVE-2023-40729 is a vulnerability in QMS Automotive that allows unencrypted communication without HTTPS, enabling an attacker to manipulate or steal confidential information.
How can the vulnerability in CVE-2023-40729 be exploited?
The vulnerability in CVE-2023-40729 can be exploited by an attacker gaining a machine-in-the-middle position.
Is there a fix available for CVE-2023-40729?
Yes, a fix is available for CVE-2023-40729. Update QMS Automotive to version V12.39 or later.