CVE-2023-40731: Malicious File Upload
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker to upload malicious files, that could potentially lead to code tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40731?
The severity of CVE-2023-40731 is high with a severity value of 8.8.
What is the affected software of CVE-2023-40731?
The affected software of CVE-2023-40731 is QMS Automotive versions prior to V12.39.
How does CVE-2023-40731 impact the affected application?
CVE-2023-40731 allows users to upload arbitrary file types, which could potentially lead to code tampering.
Is there a fix available for CVE-2023-40731?
Yes, updating to version V12.39 or later of QMS Automotive will fix CVE-2023-40731.
Where can I find more information about CVE-2023-40731?
You can find more information about CVE-2023-40731 in the reference document provided by Siemens: [link](https://cert-portal.siemens.com/productcert/pdf/ssa-147266.pdf).