Skip to main content

Vendor/product archive

siemens / qms_automotive CVEs

Beta · best-effort

11 CVEs tagged to siemens / qms_automotive1 Critical, 7 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2023-40732

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. T…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40731

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker t…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40730

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40729

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS.…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40728

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application stores sensitive application data in an external i…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40727

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated application signing mechanism.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40726

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could all…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40725

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40724

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43958

Published Nov 8, 2022

A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database wit…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1