Vulnerabilities > CVE-2023-40724 - Cleartext Storage of Sensitive Information in Memory vulnerability in Siemens QMS Automotive 12.30

047910
CVSS 7.3 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
LOW
local
low complexity
siemens
CWE-316

Summary

A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.

Vulnerable Configurations

Part Description Count
Application
Siemens
2