Vulnerabilities > CVE-2023-40729 - Unspecified vulnerability in Siemens QMS Automotive 12.30

047910
CVSS 7.4 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
high complexity
siemens

Summary

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal confidential information.

Vulnerable Configurations

Part Description Count
Application
Siemens
2