CVE-2023-40732: Low severity siemens qms automotive vulnerability
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40732?
The severity of CVE-2023-40732 is low.
What is the affected software of CVE-2023-40732?
The affected software of CVE-2023-40732 is QMS Automotive (All versions < V12.39).
What is the vulnerability description of CVE-2023-40732?
The vulnerability in CVE-2023-40732 allows an attacker to perform session hijacking attacks due to the QMS.Mobile module of the affected application not invalidating the session token on logout.
How can I fix CVE-2023-40732?
To fix CVE-2023-40732, update the affected QMS Automotive software to version 12.39 or higher.
Where can I find more information about CVE-2023-40732?
More information about CVE-2023-40732 can be found at the following reference: https://cert-portal.siemens.com/productcert/pdf/ssa-147266.pdf