CVE-2023-40726
- EPSS 0.14%
- Veröffentlicht 12.09.2023 10:15:29
- Zuletzt bearbeitet 21.11.2024 08:20:02
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the database.
CVE-2023-40727
- EPSS 0.04%
- Veröffentlicht 12.09.2023 10:15:29
- Zuletzt bearbeitet 21.11.2024 08:20:02
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated application signing mechanism. This could allow an attacker to tamper the application code.
CVE-2023-40728
- EPSS 0.06%
- Veröffentlicht 12.09.2023 10:15:29
- Zuletzt bearbeitet 21.11.2024 08:20:02
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application stores sensitive application data in an external insecure storage. This could allow an attacker to alter content, leading...
CVE-2023-40729
- EPSS 0.18%
- Veröffentlicht 12.09.2023 10:15:29
- Zuletzt bearbeitet 21.11.2024 08:20:02
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could ma...
CVE-2023-40730
- EPSS 0.12%
- Veröffentlicht 12.09.2023 10:15:29
- Zuletzt bearbeitet 21.11.2024 08:20:02
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administr...
CVE-2023-40731
- EPSS 0.16%
- Veröffentlicht 12.09.2023 10:15:29
- Zuletzt bearbeitet 21.11.2024 08:20:02
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker to upload malicious files, that could potentially lead to code tampering...
CVE-2023-40732
- EPSS 0.1%
- Veröffentlicht 12.09.2023 10:15:29
- Zuletzt bearbeitet 21.11.2024 08:20:02
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.
CVE-2023-40724
- EPSS 0.03%
- Veröffentlicht 12.09.2023 10:15:28
- Zuletzt bearbeitet 21.11.2024 08:20:01
A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.
- EPSS 0.08%
- Veröffentlicht 12.09.2023 10:15:28
- Zuletzt bearbeitet 21.11.2024 08:20:02
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an attacker to enumerate usernames, ...
CVE-2022-43958
- EPSS 0.04%
- Veröffentlicht 08.11.2022 11:15:12
- Zuletzt bearbeitet 21.11.2024 07:27:24
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access...