First published: Tue Sep 12 2023(Updated: )
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker to upload malicious files, that could potentially lead to code tampering.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Qms Automotive | <12.39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-40731 is high with a severity value of 8.8.
The affected software of CVE-2023-40731 is QMS Automotive versions prior to V12.39.
CVE-2023-40731 allows users to upload arbitrary file types, which could potentially lead to code tampering.
Yes, updating to version V12.39 or later of QMS Automotive will fix CVE-2023-40731.
You can find more information about CVE-2023-40731 in the reference document provided by Siemens: [link](https://cert-portal.siemens.com/productcert/pdf/ssa-147266.pdf).