First published: Tue Sep 12 2023(Updated: )
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal confidential information.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Qms Automotive | <12.39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-40729 is high with a CVSS score of 7.3.
The affected software of CVE-2023-40729 is QMS Automotive with all versions less than V12.39.
CVE-2023-40729 is a vulnerability in QMS Automotive that allows unencrypted communication without HTTPS, enabling an attacker to manipulate or steal confidential information.
The vulnerability in CVE-2023-40729 can be exploited by an attacker gaining a machine-in-the-middle position.
Yes, a fix is available for CVE-2023-40729. Update QMS Automotive to version V12.39 or later.