Siemens
Siemens QMS Automotive: vulnerabilidades y CVE
Siemens QMS Automotive tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-40732 | Baja (3.9) | 0.16% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform… |
| CVE-2023-40731 | Alta (8.8) | 0.55% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker to upload malicious files, that could… |
| CVE-2023-40730 | Alta (8.8) | 0.57% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential… |
| CVE-2023-40729 | Alta (7.4) | 0.29% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain… |
| CVE-2023-40728 | Alta (7.8) | 0.20% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application stores sensitive application data in an external insecure storage. This could allow an… |
| CVE-2023-40727 | Alta (7.8) | 0.13% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated application signing mechanism. This could allow an attacker to tamper… |
| CVE-2023-40726 | Alta (8.8) | 0.69% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the… |
| CVE-2023-40725 | Media (4) | 0.19% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an… |
| CVE-2023-40724 | Alta (7.3) | 0.13% | — | 12 sept 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for… |
| CVE-2022-43958 | Crítica (9.1) | 0.34% | — | 8 nov 2022 | A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could… |
| CVE-2021-27389 | Crítica (9.8) | 1.0% | — | 22 abr 2021 | A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30). A private sign key is shipped with the product without adequate protection. |